reality-check
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes the
aocommand-line utility for goal measurement (measure,validate,drift,history,export,meta,scenarios,render) and status checks (ao status). - [COMMAND_EXECUTION]: The skill runs local shell scripts
scripts/validate-output.shandscripts/validate.shto perform integrity checks on generated reports and its own configuration. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data sources (source code, artifacts,
GOALS.md) which could contain malicious instructions meant to influence the reality check report. - Ingestion points: Reads claims from source documents, repository artifacts, command outcomes, and goal files (
GOALS.mdor legacy YAML). - Boundary markers: The instructions provide clear constraints to report only facts and gaps, prohibiting the agent from issuing a 'verdict' or 'PASS' and from selecting new work based on findings.
- Capability inventory: File system writes to
.agents/scratch/and.agents/ao/goals/baselines/, execution of theaoCLI tool, and execution of local shell scripts. - Sanitization: No explicit sanitization or filtering of evidence content is mentioned before it is included in the report findings.
- [DATA_EXPOSURE]: Accesses internal platform metadata and artifact stores located in
.agents/ao/intents/and.agents/ao/verdicts/to report recency and recency of evidence.
Audit Metadata