workspace-planning
Pass
Audited by Gen Agent Trust Hub on Apr 2, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of
pyyamlvia pip. This is a well-known and standard library for parsing YAML data. - [COMMAND_EXECUTION]: The skill executes a local script
scripts/planning.pyto perform deterministic operations like reviewing progress, updating statuses, and linking project changes. The script usesyaml.safe_load()to prevent YAML-based injection attacks. - [DATA_EXPOSURE_AND_EXFILTRATION]: No network operations or unauthorized data access were identified. The script only interacts with project-specific YAML files in the
planning/schedules/directory. - [INDIRECT_PROMPT_INJECTION]: While the skill processes external YAML data, it employs a state machine to validate all status transitions and uses safe parsing methods, effectively mitigating risks associated with untrusted data ingestion.
Audit Metadata