skills/uinaf/agent-skills/planning/Gen Agent Trust Hub

planning

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill implements explicit safeguards for handling sensitive data. In the 'Tracker Selection' guidelines and the main workflow, it instructs the agent to identify potentially sensitive details, such as unpatched vulnerabilities, and requires explicit user confirmation or the selection of a private destination before any external write operation is performed.
  • [SAFE]: The skill adheres to the principle of least privilege by using only the repository's established tracking tools and authenticated CLI connectors. It contains specific prohibitions against installing unauthorized integrations or altering security configurations to facilitate task creation.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources, including conversation logs, source files, and existing tracker issues, to generate plans. While this represents a surface for indirect prompt injection, the risk is addressed through instructions to verify facts against the current repository state, preserve only settled intent, and provide a compact summary for user review before completion.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 12:16 PM
Security Audit — agent-trust-hub — planning