skills/nsantini/gsdl/gsdl-create-plan/Gen Agent Trust Hub

gsdl-create-plan

Pass

Audited by Gen Agent Trust Hub on Mar 12, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes Product Requirements Documents (PRDs) from the local file system, creating a surface for indirect prompt injection. 1. Ingestion points: Reads .planning/[project-name]/tasks/prd-[feature-name].md in SKILL.md. 2. Boundary markers: No explicit boundary markers or instructions to ignore embedded commands are provided for the PRD content. 3. Capability inventory: The skill has file-write capabilities for saving task lists. 4. Sanitization: No sanitization of the PRD content is performed. Note: The multi-phase interaction model requiring a human 'Go' command before phase 2 significantly mitigates the risk of automated command execution from injected content.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 12, 2026, 07:23 PM