plan-ceo-review

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted repository data (e.g., AGENTS.md, TODO.md, and code files) to guide the agent's review process.
  • Ingestion points: The PRE-REVIEW SYSTEM AUDIT section in SKILL.md instructs the agent to read project-local instructions, architecture documents, and source code files.
  • Boundary markers: The instructions do not define delimiters or provide specific warnings to the agent to ignore embedded instructions found within the repository files.
  • Capability inventory: The skill uses subprocess calls to execute read-only commands (git log, git diff, git stash, grep, find) in SKILL.md. It explicitly forbids making code changes or starting implementation during the review phase.
  • Sanitization: There is no evidence of sanitization, validation, or escaping of the content ingested from the external repository files before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 06:54 AM
Security Audit — agent-trust-hub — plan-ceo-review