planning-and-task-breakdown

Pass

Audited by Gen Agent Trust Hub on May 7, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes external specifications and uses the content to generate shell commands and file content.- [INGESTION_POINTS]: SKILL.md (Process section) instructions to 'Read the Spec' and 'Map Stories to Tasks'.- [BOUNDARY_MARKERS]: None identified in the prompt templates or instructions to isolate untrusted specification text.- [CAPABILITY_INVENTORY]: Execution of 'solo task create' via shell and creation of markdown files in the 'specs/' directory.- [SANITIZATION]: No specific instructions provided for the agent to sanitize or escape input derived from external specifications.- [COMMAND_EXECUTION]: Executes shell commands to interface with the 'solo' task management tool and to verify the local environment using standard tools like 'test' and 'which'.
Audit Metadata
Risk Level
SAFE
Analyzed
May 7, 2026, 03:48 PM
Security Audit — agent-trust-hub — planning-and-task-breakdown