doc-iplan-autopilot

Fail

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: HIGHCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill requires the agent to execute a Python script located at a path defined by an environment variable.
  • Evidence: python3 "${CLAUDE_PLUGIN_ROOT}/tools/saga_driver.py" --layer 08_IPLAN --allow-skip-permissions.
  • [PRIVILEGE_ESCALATION]: The instructions explicitly command the agent to use a specific flag to bypass platform-level safety and permission prompts for file system operations.
  • Evidence: The prompt instructs the agent to run the driver with --allow-skip-permissions, stating it "lets the phases the driver dispatches write files without a permission prompt — unattended autopilot requires it."
  • [INDIRECT_PROMPT_INJECTION]: The skill has a significant attack surface for indirect prompt injection as it processes untrusted upstream artifacts and external configuration files to drive automated logic.
  • Ingestion points: Processes SPEC, TDD, and user prompts from the workspace, as well as configuration files like .aidoc/profile.yaml and .claude/aidoc-flow.config.yaml.
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to ignore embedded instructions within the ingested SPEC or TDD files.
  • Capability inventory: The skill utilizes the Bash tool to perform extensive file modifications and index updates.
  • Sanitization: There is no evidence of sanitization or validation of the contents of the upstream artifacts before they are used to generate the IPLAN or influence the state machine.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 17, 2026, 09:07 PM
Security Audit — agent-trust-hub — doc-iplan-autopilot