Generate a Plan Brief HTML for non-engineer vibecoders before implementation starts. Searches harness-mem (project-only) for relevant past decisions, patterns, and Plans archive entries, then renders a single-file HTML artifact summarizing understanding, options, risks, acceptance criteria, and confidence. Use when the user requests a planning preview, a non-engineer-friendly summary before approval, or says: plan brief, planning preview, 計画概要, 計画レビュー. Do NOT load for: actual implementation, code review, release work.
The canonical home for this skill is harness-plan-brief in Chachamaru127/claude-code-harness
Low
Low-risk findings.
1 low severity finding. Worth noting, but not necessarily harmful.
The skill exposes the agent to untrusted, user-generated content from public third-party sources, creating a risk of indirect prompt injection. This includes browsing arbitrary URLs, reading social media posts or forum comments, and analyzing content from unknown websites.
Step 2でユーザー入力([task-description])を `mcp__harness__harness_mem_search` の `query` として用い、その検索結果(過去 decision/pattern/plans archive 由来の文字列)を `scripts/plan-brief-compile.sh` が読み取り context JSON/HTML に組み込むため、アウトサイダーが“プロジェクトのキュー/フィードへ投稿して読ませる”ことで間接プロンプト注入が成立し得ます。
7d8deba
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.