plannotator
Fail
Audited by Gen Agent Trust Hub on Mar 7, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The
scripts/install.shscript executes a remote script usingcurl -fsSL https://plannotator.ai/install.sh | bash. This pattern allows an external server to execute arbitrary code on the local system without prior verification. - [EXTERNAL_DOWNLOADS]: The skill attempts to download and install its CLI component from
plannotator.ai, which is not a recognized trusted source or a verified resource belonging to the author 'supercent-io'. - [COMMAND_EXECUTION]: Several scripts perform automated modifications to local configuration files. For example,
scripts/setup-hook.shandscripts/setup-gemini-hook.shuse Python scripts to merge command strings into~/.claude/settings.jsonand~/.gemini/settings.json. - [DATA_EXPOSURE]: The skill accesses and modifies sensitive application settings in hidden directories like
~/.claude/,~/.gemini/, and~/.codex/. - [COMMAND_EXECUTION]: The script
scripts/configure-remote.shmodifies system shell profiles such as.bashrcand.zshrcto inject environment variables, which functions as a persistence mechanism to alter the shell environment across sessions. - [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface.
- Ingestion points: The
scripts/review.shscript and the plan submission process ingest untrusted data from git diffs and implementation plans. - Boundary markers: No explicit safety delimiters or 'ignore embedded instructions' warnings are present in the scripts handling the data.
- Capability inventory: The skill provides automated scripts for shell command execution, file modification, and environment configuration.
- Sanitization: The skill does not perform sanitization or validation of the input plan or diff content before it is processed by the tools.
Recommendations
- HIGH: Downloads and executes remote code from: https://plannotator.ai/install.sh - DO NOT USE without thorough review
- AI detected serious security threats
Audit Metadata