writing-plans
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- Indirect Prompt Injection (LOW): The skill defines a process where external project specifications are used to generate detailed tasks and commands. Ingestion points: The skill takes 'specs or requirements' as input for generating plan documents. Boundary markers: There are no defined delimiters or instructions to prevent the agent from following malicious commands hidden within the provided specs. Capability inventory: The generated plans include instructions for writing files to 'docs/plans/' and executing shell commands like 'pytest' and 'git'. Sanitization: There is no mention of sanitizing or validating the input requirements before they are incorporated into the plan and presented for execution.
Audit Metadata