craft-goal
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted user data (outcomes and acceptance criteria) and interpolates it into a complex 'Mayor-style' prompt template. This generated prompt is intended to control a persistent agent runtime. If the input data contains malicious instructions, they could influence the downstream agent's logic or security posture.
- Ingestion points: The skill consumes
caller-outcomeandgoal-acceptanceas defined in theSKILL.mdfrontmatter. - Boundary markers: The template in
references/goal-prompt.mduses angle-bracket placeholders for user input but does not specify delimiters or sanitization rules to isolate user text from the prompt's instructional logic. - Capability inventory: The skill specifies interaction with the
bdtracker tool for persistent state and mutation, and the generated prompt is designed to orchestrate experiments with authority over internal tools. - Sanitization: No explicit validation, escaping, or filtering of the user-provided strings is described before they are included in the emitted prompt.
- [COMMAND_EXECUTION]: The skill involves the execution of shell commands for validation and state tracking.
- Evidence: The file
scripts/validate.shexecutes a bash script usingexec bash. - Evidence:
SKILL.mdinstructs the agent to 'verify bd context --json before mutation', which involves calling a CLI tool. - Evidence:
SKILL.mdprovides a shell snippet usingprintf,head, andgrepfor output validation. - [DYNAMIC_EXECUTION]: The skill uses a validation script that determines the location of and executes another script at runtime based on its own file system position.
- Evidence:
scripts/validate.shcalculatesREPO_ROOTusing shell subshells and then executes a script located at$REPO_ROOT/skills/skill-builder/scripts/heal.sh.
Audit Metadata