design-strategic-goals
Pass
Audited by Gen Agent Trust Hub on May 9, 2026
Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill operates entirely within the project documentation scope to generate strategic goals based on existing documents like vision and North Star files. This behavior is consistent with its stated purpose of documentation management.
- [NO_CODE]: The skill files do not contain any executable scripts, binary files, or external code dependencies, relying solely on natural language instructions for the agent.
- [PROMPT_INJECTION]: The skill has an inherent surface for indirect prompt injection. 1. Ingestion points: reads docs/project-overview/vision.md, docs/project-overview/north-star.md, and docs/project-overview/strategic-pillars.md. 2. Boundary markers: Absent. 3. Capability inventory: Writing markdown to docs/project-overview/strategic-goals.md. 4. Sanitization: Absent. The risk is assessed as safe because the skill has no dangerous capabilities such as network access or shell execution.
Audit Metadata