goalify
Pass
Audited by Gen Agent Trust Hub on Jul 2, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides structured instructions for automating project tasks using a defined workflow. No malicious behavior was detected.
- [COMMAND_EXECUTION]: The skill describes a process for archiving design documents to
docs/worklog/and managing Git branches. These actions are within the expected scope of a development-oriented agent skill. - [DATA_EXPOSURE]: The skill accesses project-specific files such as specifications, validation contracts, and PR descriptions to build task context. This is limited to the project directory and does not target sensitive system credentials or private keys.
- [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted data from external sources like GitHub Issues or PR descriptions. While this creates an attack surface for indirect prompt injection, the skill mitigates this by requiring a structured output format for goals and establishing explicit human-in-the-loop checkpoints where the agent must ask the user to confirm the goal's completion criteria.
Audit Metadata