collaborative-plan-with-file
Pass
Audited by Gen Agent Trust Hub on Mar 25, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local shell commands such as
git rev-parse,mkdir, andcp. These are utilized for environment discovery and managing the lifecycle of planning artifacts within the project's.workflowdirectory. - [DATA_EXFILTRATION]: The skill reads project documentation and source code to identify planning context. Analysis shows no network operations or exfiltration patterns that would send this data to external or untrusted endpoints.
- [REMOTE_CODE_EXECUTION]: No patterns for downloading and executing remote scripts (e.g.,
curl | bash) were detected. The execution logic relies on predefined local workflow steps and established project tools. - [PROMPT_INJECTION]: The instructions focus on planning structure and logic. No evidence was found of attempts to override agent safety guidelines, extract system prompts, or bypass operational constraints.
Audit Metadata