ce-plan
Pass
Audited by Gen Agent Trust Hub on May 6, 2026
Risk Level: SAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill ingests untrusted data from user-supplied arguments and existing repository documentation (e.g., brainstorm files). It employs XML-style tags (
<feature_description>) as boundary markers for input interpolation, reducing the risk of indirect prompt injection. This surface is part of the core planning logic and follows established integration patterns. - [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands for lifecycle tasks, such as creating temporary directories for research artifacts via
mktempand managing project issues through theghandlinearCLI tools. These executions are scoped to the task's stated goals. - [DATA_EXFILTRATION]: The workflow includes optional steps to export generated plans to external issue trackers (GitHub, Linear) and the author's 'Proof' web service for review. These network operations are user-initiated and target well-known or vendor-managed services, presenting no unauthorized data exposure risk.
Audit Metadata