architect-plan

Pass

Audited by Gen Agent Trust Hub on Apr 9, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill employs a specialized subagent (Doc Discovery Agent) to fetch and analyze information from external API documentation and library references.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface due to its reliance on external data sources for plan generation.
  • Ingestion points: Technical documentation fetched from the web (agents/doc-discovery-agent.md) and task details retrieved from Jira tickets (SKILL.md).
  • Boundary markers: The instructions do not specify the use of delimiters or 'ignore' directives to isolate external content from the agent's core instructions.
  • Capability inventory: The skill has permissions to write files to the local repository (enggenie/ directory) and post comments to external project management tools (Jira).
  • Sanitization: No explicit sanitization or validation of external input is described in the provided logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 9, 2026, 11:30 AM