define-mission

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from various local repositories (~/repos/*), PRDs, and user conversations to define a global mission. If these source files contain malicious instructions, they could influence the generated mission and be propagated to other projects.
  • Ingestion points: The skill reads ~/repos/*/CHOICES.md, README.md, and external objective/metric documents during the detection and interview phases.
  • Boundary markers: There are no explicit markers or 'ignore embedded instructions' directives provided when processing the repository content or external PRDs.
  • Capability inventory: The skill possesses the ability to write to ~/vault/missions.md and dispatches the /apply-mission skill, which likely performs file writes across multiple repositories.
  • Sanitization: The skill does not specify methods for sanitizing, escaping, or validating the content read from local repositories before incorporating it into the global mission definition or the missions.md file.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 08:52 PM
Security Audit — agent-trust-hub — define-mission