plan-eng-review

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest instructions from repository-local files such as AGENTS.md, TODO.md, and TODOS.md. While this is the intended primary purpose of the skill to provide context-aware reviews, it creates a surface where contents of those files could influence agent behavior.
  • Ingestion points: Mentions AGENTS.md, TODO.md, and TODOS.md in SKILL.md as sources of repo-local instructions.
  • Boundary markers: None explicitly implemented within the skill to delimit external file content.
  • Capability inventory: The skill facilitates file review and suggested modifications, operating within the agent's standard file system access capabilities.
  • Sanitization: No explicit sanitization or filtering of the content within the referenced local files is defined.
  • [SAFE]: The skill consists entirely of markdown instructions and does not include any executable code, scripts, or binary files.
  • [SAFE]: No network operations, remote code execution patterns, or data exfiltration vectors were detected.
  • [SAFE]: The YAML frontmatter and skill metadata are consistent with the described functionality and contain no deceptive or malicious content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 06:54 AM
Security Audit — agent-trust-hub — plan-eng-review