plan-founder-review

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues were detected. The skill is designed to perform technical audits of implementation plans by verifying them against the actual codebase using standard diagnostic tools (Read, Glob, Grep, Bash).
  • [SAFE]: The skill uses a forked context and is read-only, explicitly instructing the agent not to modify files during the review process. This limits the potential for unauthorized changes to the project.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted implementation plan data from the .ulpi/plans/ directory. While this is an attack surface, the instructions specifically command the agent to verify plan claims against the actual repository rather than trusting the plan text, which serves as a defensive boundary. The potential impact is low given the read-only and diagnostic nature of the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:24 PM
Security Audit — agent-trust-hub — plan-founder-review