architect-plan
Pass
Audited by Gen Agent Trust Hub on Apr 9, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill employs a specialized subagent (Doc Discovery Agent) to fetch and analyze information from external API documentation and library references.
- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface due to its reliance on external data sources for plan generation.
- Ingestion points: Technical documentation fetched from the web (agents/doc-discovery-agent.md) and task details retrieved from Jira tickets (SKILL.md).
- Boundary markers: The instructions do not specify the use of delimiters or 'ignore' directives to isolate external content from the agent's core instructions.
- Capability inventory: The skill has permissions to write files to the local repository (enggenie/ directory) and post comments to external project management tools (Jira).
- Sanitization: No explicit sanitization or validation of external input is described in the provided logic.
Audit Metadata