goal-drift

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes standard system binaries to gather evidence for its audit process. It uses subprocess.run to call git for commit history and gh for GitHub issue data, but passes all arguments as lists rather than shell strings, effectively preventing command injection. This usage is found in src/goal_drift/evidence.py, src/goal_drift/core.py, and src/goal_drift/cli.py. The skill even includes a self-test in sanity.sh that uses AST inspection to verify that no mutating git verbs are used.
  • [PROMPT_INJECTION]: The skill processes external data from GitHub issues, which represents an indirect prompt injection surface. The ingestion occurs in src/goal_drift/evidence.py through the gather_tickets function. This is mitigated by the skill's read-only nature and its use of keyword-based matching rather than direct instruction execution. Data integrity is enforced via typed "Seam Contracts" in src/goal_drift/contracts.py that validate all incoming artifacts.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:01 PM
Security Audit — agent-trust-hub — goal-drift