executing-plans
Pass
Audited by Gen Agent Trust Hub on Jun 26, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides a standard procedural framework for an AI agent to execute tasks with no detected malicious patterns, obfuscation, or unauthorized operations.
- [PROMPT_INJECTION]: Analysis of the indirect prompt injection surface identifies the following factors:
- Ingestion points: The agent reads an external 'plan file' in Step 1 of the process.
- Boundary markers: No explicit markers or delimiters are defined to separate plan data from instructions.
- Capability inventory: The agent is instructed to 'follow each step exactly' and 'run verifications,' which could include shell commands or script execution.
- Sanitization: There is no explicit sanitization of the plan file content.
- Context: The risk is effectively mitigated by the 'Review critically' requirement and the mandatory instruction to raise concerns with a human partner before execution begins.
Audit Metadata