goal
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPERSISTENCECOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill accepts user-provided goal objectives that are stored in a local database and later interpolated into the agent's instructions during subsequent turns. This creates a surface where malicious instructions could be persisted and executed by the agent.\n
- Ingestion points: User input provided via the
/goalcommand is captured inSKILL.md(as$ARGUMENTS) and processed byscripts/claude_goal.py.\n - Boundary markers: The objective is delimited by
<objective>tags in the prompt instructions generated by the Python script.\n - Capability inventory: The skill can execute local Python logic and modify a SQLite database. The agent itself possesses file system and command execution capabilities that could be targeted by a malicious objective.\n
- Sanitization: The script enforces a 4000-character limit on objectives and the instructions explicitly warn the agent not to follow instructions within the objective that conflict with system or user messages.\n- [PERSISTENCE]: The skill implements a persistent state for goals and a mechanism to influence agent behavior across sessions.\n
- State Storage: Goal data is persisted in a SQLite database located at
~/.claude/goal/goals.sqlite.\n - Execution Hook: The
stop_hookfunction inscripts/claude_goal.pyallows the skill to block the agent's termination signal when a goal is active, effectively maintaining the agent's focus until the goal is completed or paused.\n- [COMMAND_EXECUTION]: The skill relies on executing a local Python script to handle its core logic. User-provided arguments are passed to this script, though they are handled usingshlex.splitto mitigate shell injection risks during parsing.
Audit Metadata