plan-eng-review
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest instructions from repository-local files such as
AGENTS.md,TODO.md, andTODOS.md. While this is the intended primary purpose of the skill to provide context-aware reviews, it creates a surface where contents of those files could influence agent behavior. - Ingestion points: Mentions
AGENTS.md,TODO.md, andTODOS.mdinSKILL.mdas sources of repo-local instructions. - Boundary markers: None explicitly implemented within the skill to delimit external file content.
- Capability inventory: The skill facilitates file review and suggested modifications, operating within the agent's standard file system access capabilities.
- Sanitization: No explicit sanitization or filtering of the content within the referenced local files is defined.
- [SAFE]: The skill consists entirely of markdown instructions and does not include any executable code, scripts, or binary files.
- [SAFE]: No network operations, remote code execution patterns, or data exfiltration vectors were detected.
- [SAFE]: The YAML frontmatter and skill metadata are consistent with the described functionality and contain no deceptive or malicious content.
Audit Metadata