goal-prompting

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the local repository (such as logs, issues, and third-party scripts) to generate autonomous goal prompts.
  • Ingestion Points: SKILL.md identifies repository instructions, plans, tests, scripts, issues, and logs as context sources for drafting goals.
  • Boundary Markers: The skill enforces a 'Shared Goal Contract' that requires explicit constraints, material boundaries, and real stop conditions to delimit agent behavior.
  • Capability Inventory: Capabilities include reading repository files and activating harness-native goal states via session APIs or user-submitted slash commands.
  • Sanitization: The skill includes a mandatory 'Audit' phase to detect false completion, unverified assumptions, and target-specific blind spots before a goal is presented or activated.
  • [EXTERNAL_DOWNLOADS]: The references/source-notes.md file contains a detailed bibliography of external sources.
  • Evidence: Provides plain-text links to official documentation from OpenAI and Anthropic, as well as several community skill repositories on GitHub used for research and comparison.
  • Context: These links are provided as 'Prior Art' and 'Official Sources' for maintainability and do not represent scripts to be downloaded or executed at runtime.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 12:17 PM
Security Audit — agent-trust-hub — goal-prompting