goal-drift
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes standard system binaries to gather evidence for its audit process. It uses
subprocess.runto callgitfor commit history andghfor GitHub issue data, but passes all arguments as lists rather than shell strings, effectively preventing command injection. This usage is found insrc/goal_drift/evidence.py,src/goal_drift/core.py, andsrc/goal_drift/cli.py. The skill even includes a self-test insanity.shthat uses AST inspection to verify that no mutating git verbs are used. - [PROMPT_INJECTION]: The skill processes external data from GitHub issues, which represents an indirect prompt injection surface. The ingestion occurs in
src/goal_drift/evidence.pythrough thegather_ticketsfunction. This is mitigated by the skill's read-only nature and its use of keyword-based matching rather than direct instruction execution. Data integrity is enforced via typed "Seam Contracts" insrc/goal_drift/contracts.pythat validate all incoming artifacts.
Audit Metadata