goal-prompting
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the local repository (such as logs, issues, and third-party scripts) to generate autonomous goal prompts.
- Ingestion Points:
SKILL.mdidentifies repository instructions, plans, tests, scripts, issues, and logs as context sources for drafting goals. - Boundary Markers: The skill enforces a 'Shared Goal Contract' that requires explicit constraints, material boundaries, and real stop conditions to delimit agent behavior.
- Capability Inventory: Capabilities include reading repository files and activating harness-native goal states via session APIs or user-submitted slash commands.
- Sanitization: The skill includes a mandatory 'Audit' phase to detect false completion, unverified assumptions, and target-specific blind spots before a goal is presented or activated.
- [EXTERNAL_DOWNLOADS]: The
references/source-notes.mdfile contains a detailed bibliography of external sources. - Evidence: Provides plain-text links to official documentation from OpenAI and Anthropic, as well as several community skill repositories on GitHub used for research and comparison.
- Context: These links are provided as 'Prior Art' and 'Official Sources' for maintainability and do not represent scripts to be downloaded or executed at runtime.
Audit Metadata