plannotator-annotate

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes the plannotator command with context-derived arguments using a bash shell. Evidence: Found in SKILL.md as plannotator annotate $ARGUMENTS.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection by acting upon feedback returned from tool outputs.
  • Ingestion points: Feedback content provided in the output of the plannotator annotate command as described in SKILL.md.
  • Boundary markers: Absent; the skill lacks instructions to delimit or ignore potentially malicious instructions within the feedback.
  • Capability inventory: Execution of shell commands via the plannotator tool and subsequent model interaction based on its output.
  • Sanitization: Absent; the skill instructs the agent to address feedback directly within the conversation without filtering.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 05:13 PM
Security Audit — agent-trust-hub — plannotator-annotate