hivemind-goals
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements a 'park and resume' workflow that stores arbitrary session context for future use.
- Ingestion points: User input provided when creating goals or capturing tasks in
SKILL.mdvia bash heredocs or thehivemind goalCLI. - Boundary markers: The skill lacks explicit delimiters or instructions to treat resumed content as untrusted data.
- Capability inventory: The agent has access to
Bashfor file operations andReadfor accessing files, alongside thehivemindCLI. - Sanitization: The instructions recommend using quoted heredocs (
<<'EOF') which prevents immediate shell expansion during the writing process, but no validation is performed on the content when it is retrieved and followed during the 'resume' phase. - [COMMAND_EXECUTION]: The skill uses the
Bashtool to interact with the Deeplake virtual filesystem. - It provides templates for using standard shell utilities like
cat,mv, andrmto manage state at~/.deeplake/memory/goal/. - The instructions explicitly guide the agent on how to use
bashto bypass tool restrictions on specific memory paths where direct write/edit tools are denied.
Audit Metadata