plannotator-annotate
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes the
plannotatorcommand with context-derived arguments using a bash shell. Evidence: Found inSKILL.mdasplannotator annotate $ARGUMENTS. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection by acting upon feedback returned from tool outputs.
- Ingestion points: Feedback content provided in the output of the
plannotator annotatecommand as described inSKILL.md. - Boundary markers: Absent; the skill lacks instructions to delimit or ignore potentially malicious instructions within the feedback.
- Capability inventory: Execution of shell commands via the
plannotatortool and subsequent model interaction based on its output. - Sanitization: Absent; the skill instructs the agent to address feedback directly within the conversation without filtering.
Audit Metadata