skills/xgent-ai/skills/dev-plan/Gen Agent Trust Hub

dev-plan

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides a structured methodology for technical planning and contains no malicious instructions or patterns. It operates locally within the project directory and does not request network access or sensitive system credentials.
  • [COMMAND_EXECUTION]: The skill uses local utility scripts (scripts/check_paths.sh and scripts/check_progress.sh) for plan validation. These scripts are implemented securely, utilizing strict regular expression filtering to ensure that only valid, safe file paths are processed, effectively preventing any command injection from plan content.
  • [INDIRECT_PROMPT_INJECTION]: While the skill ingests project data and user requirements to generate plans, it incorporates architectural quality gates and fact-checking requirements that reduce the risk of following malicious instructions embedded in codebase documents.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 03:32 PM
Security Audit — agent-trust-hub — dev-plan