goal-driven
Pass
Audited by Gen Agent Trust Hub on Jul 22, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes standard development commands such as
npm test,npm run lint, andgit statusto verify goal completion conditions. - [REMOTE_CODE_EXECUTION]: The instructions suggest using package management commands like
npm install <pkg>to address missing dependencies during autonomous execution. - [PROMPT_INJECTION]: The skill is designed to ingest data from project-specific files (e.g.,
.forgewright/project-profile.json,TASKS.md) to establish context, which presents a surface for indirect prompt injection. 1. Ingestion points: Local configuration and source files are read during the grounding and decomposition phases. 2. Boundary markers: There are no explicit instructions for using delimiters to isolate data from these files. 3. Capability inventory: The agent is empowered to execute shell commands and modify files autonomously. 4. Sanitization: The skill does not specify methods for sanitizing the content retrieved from project files.
Audit Metadata