goal-driven

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes standard development commands such as npm test, npm run lint, and git status to verify goal completion conditions.
  • [REMOTE_CODE_EXECUTION]: The instructions suggest using package management commands like npm install <pkg> to address missing dependencies during autonomous execution.
  • [PROMPT_INJECTION]: The skill is designed to ingest data from project-specific files (e.g., .forgewright/project-profile.json, TASKS.md) to establish context, which presents a surface for indirect prompt injection. 1. Ingestion points: Local configuration and source files are read during the grounding and decomposition phases. 2. Boundary markers: There are no explicit instructions for using delimiters to isolate data from these files. 3. Capability inventory: The agent is empowered to execute shell commands and modify files autonomously. 4. Sanitization: The skill does not specify methods for sanitizing the content retrieved from project files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 08:30 AM
Security Audit — agent-trust-hub — goal-driven