doc-iplan-fixer
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it is designed to ingest and parse untrusted external data from
.aidoc/audit/08_IPLAN-audit.mdto determine necessary file modifications. However, the risk is mitigated by the 'team mode' architecture, which dispatches specialized subagents to validate every blocking patch before it is finalized, preventing the adoption of regressive or malicious instructions contained within the audit data. - [COMMAND_EXECUTION]: The skill utilizes shell commands (via
Bash:blocks) to perform routine metadata tasks such as directory creation (mkdir -p), generating timestamps (date +%s), and calculating execution elapsed time for timeout enforcement. These operations are restricted to the project's internal.aidocmetadata directory and do not involve sensitive system paths or privileged operations. - [DYNAMIC_CONTEXT_INJECTION]: While the skill contains shell commands within the instructions, they are intended for manual or agent-driven execution during the remediation process rather than hidden 'at load' execution. The commands are transparently documented and used for managing the 'saga' state journal.
- [DATA_EXPOSURE]: The skill reads project-level configuration files (
.aidoc/profile.yaml) and framework governance files to ensure compliance with ID naming and authoring standards. It performs local backups of artifacts before modification, which is a security best practice for data integrity. No evidence of credential harvesting or external data exfiltration was found.
Audit Metadata