ablation-planner

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill is granted Bash(*) permissions and is designed to execute shell commands and scripts based on plans designed by an external model (mcp__codex__codex). This creates a risk where instructions from an external source directly drive system-level execution.
  • [DYNAMIC_EXECUTION]: The workflow in Step 5 involves the automated creation of configuration files and shell scripts at runtime. These generated assets are then executed, which increases the attack surface by allowing the execution of logic not present in the original skill.
  • [DATA_EXFILTRATION]: The skill reads project files such as CLAUDE.md, which often contains environment variables and server configurations, and EXPERIMENT_LOG.md. This data is then sent to an external service via the mcp__codex__codex tool, potentially exposing sensitive local environment details.
  • [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection as it ingests untrusted data from various project files and interpolates it directly into a prompt for an external LLM.
  • Ingestion points: The skill reads research_contract.md, EXPERIMENT_LOG.md, and CLAUDE.md from the local file system.
  • Boundary markers: No delimiters or "ignore embedded instructions" warnings are used when inserting file content into the Codex prompt.
  • Capability inventory: The agent has extensive capabilities including Bash(*), Write, and Edit, which can be leveraged if the external model is manipulated.
  • Sanitization: There is no evidence of filtering or sanitization of the content read from files before it is processed by the model.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 02:07 PM
Security Audit — agent-trust-hub — ablation-planner