ralplan

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes a suite of platform-specific CLI tools, such as omx ralplan, omx question, and omx sparkshell, to manage the planning lifecycle, interact with the user, and gather read-only repository evidence. These tools are used for workflow orchestration and state management within the .omx/ directory.
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a governance layer that processes untrusted user input (task descriptions) to drive its planning workflow. It includes a specific 'Pre-Execution Gate' logic to identify and redirect vague or potentially malicious prompts into a structured review cycle.
  • Ingestion points: User-provided task descriptions supplied via the $ralplan command and subsequent user feedback during interactive review sessions.
  • Boundary markers: The workflow uses structured JSON artifacts (e.g., ralplan_execution_handoff) and explicit role-based transitions (Planner -> Architect -> Critic) to isolate planning data from execution authority.
  • Capability inventory: The skill can execute local omx tools for status reporting, evidence collection, and subagent invocation, and it has write access to the .omx/ metadata directory.
  • Sanitization: A multi-agent consensus loop is enforced, requiring both an 'Architect' subagent and a 'Critic' subagent to approve the generated plan before any transition to execution modes is permitted.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 04:53 PM
Security Audit — agent-trust-hub — ralplan