planning-and-task-breakdown
Pass
Audited by Gen Agent Trust Hub on May 7, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes external specifications and uses the content to generate shell commands and file content.- [INGESTION_POINTS]: SKILL.md (Process section) instructions to 'Read the Spec' and 'Map Stories to Tasks'.- [BOUNDARY_MARKERS]: None identified in the prompt templates or instructions to isolate untrusted specification text.- [CAPABILITY_INVENTORY]: Execution of 'solo task create' via shell and creation of markdown files in the 'specs/' directory.- [SANITIZATION]: No specific instructions provided for the agent to sanitize or escape input derived from external specifications.- [COMMAND_EXECUTION]: Executes shell commands to interface with the 'solo' task management tool and to verify the local environment using standard tools like 'test' and 'which'.
Audit Metadata