hivemind-goals

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a 'park and resume' workflow that stores arbitrary session context for future use.
  • Ingestion points: User input provided when creating goals or capturing tasks in SKILL.md via bash heredocs or the hivemind goal CLI.
  • Boundary markers: The skill lacks explicit delimiters or instructions to treat resumed content as untrusted data.
  • Capability inventory: The agent has access to Bash for file operations and Read for accessing files, alongside the hivemind CLI.
  • Sanitization: The instructions recommend using quoted heredocs (<<'EOF') which prevents immediate shell expansion during the writing process, but no validation is performed on the content when it is retrieved and followed during the 'resume' phase.
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to interact with the Deeplake virtual filesystem.
  • It provides templates for using standard shell utilities like cat, mv, and rm to manage state at ~/.deeplake/memory/goal/.
  • The instructions explicitly guide the agent on how to use bash to bypass tool restrictions on specific memory paths where direct write/edit tools are denied.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 03:19 AM