define-mission
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from various local repositories (
~/repos/*), PRDs, and user conversations to define a global mission. If these source files contain malicious instructions, they could influence the generated mission and be propagated to other projects. - Ingestion points: The skill reads
~/repos/*/CHOICES.md,README.md, and external objective/metric documents during the detection and interview phases. - Boundary markers: There are no explicit markers or 'ignore embedded instructions' directives provided when processing the repository content or external PRDs.
- Capability inventory: The skill possesses the ability to write to
~/vault/missions.mdand dispatches the/apply-missionskill, which likely performs file writes across multiple repositories. - Sanitization: The skill does not specify methods for sanitizing, escaping, or validating the content read from local repositories before incorporating it into the global mission definition or the
missions.mdfile.
Audit Metadata