skills/udecode/plate/slate-plan/Gen Agent Trust Hub

slate-plan

Pass

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides a robust and transparent framework for managing complex architectural changes with multiple security checkpoints and verification gates.
  • [COMMAND_EXECUTION]: The skill executes local development commands such as 'bun' for testing, 'rg' (grep) for symbol discovery, and 'node' for internal lifecycle management. All commands are executed within the project context ('.tmp/slate-v2' or 'plate-2') and are essential for its stated development purpose.
  • [EXTERNAL_DOWNLOADS]: The skill interacts with GitHub via the 'gh' CLI to track and update issue status. GitHub is a well-known service, and the operations are limited to reading/writing metadata and comments within the specific project's issue corpus.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it processes external content from GitHub issues and project documentation. 1. Ingestion points: Data from GitHub issue threads and local ledgers. 2. Boundary markers: No explicit delimiters are used for untrusted content. 3. Capability inventory: Ability to execute shell commands and modify code in the implementation workspace. 4. Sanitization: No specific sanitization logic is detailed. However, the risk is effectively mitigated by the skill's hard policy requiring explicit user review and a separate invocation for execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 2, 2026, 05:10 PM
Security Audit — agent-trust-hub — slate-plan