doc-iplan
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is entirely instructional markdown that defines a YAML schema for technical documentation. It does not contain executable scripts, network requests, or credential harvesting patterns.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from upstream 'SPEC' and 'TDD' files to generate an implementation plan. While this presents a potential ingestion surface for indirect prompt injection, it is a standard functional requirement for documentation workflows.
- Ingestion points: Reads local files tagged as
@specand@tdd. - Boundary markers: None explicitly defined in the provided file manifest instructions.
- Capability inventory: File reading (
ls), and authoring of YAML documentation. - Sanitization: No specific sanitization logic is described for the content of the upstream artifacts.
Audit Metadata