clarify-goal

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external documents provided by the user, which could contain embedded malicious instructions.
  • Ingestion points: Content is read and scanned from external files provided via the paper-path argument as described in Step 1.
  • Boundary markers: The instructions do not specify any delimiters or safety warnings to the agent to treat the document content strictly as data.
  • Capability inventory: The skill has the capability to write files to the local file system at reaper-workspace/notes/clarified-goal.md as described in Step 4.
  • Sanitization: There is no process for validating or sanitizing the content extracted from the paper before it is used to generate the clarifying questions or the final research goal summary.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 08:28 AM
Security Audit — agent-trust-hub — clarify-goal