autoresearch-goal

Pass

Audited by Gen Agent Trust Hub on May 6, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes a CLI tool named omx to manage research workflows. The command omx autoresearch-goal create includes a --critic-command parameter, which allows the specification of a command to be used for research validation. This is a functional feature of the workflow and does not target sensitive system areas.- [PROMPT_INJECTION]: The skill processes untrusted research topics and rubrics, creating a surface for indirect prompt injection.
  • Ingestion points: Input enters the system via the --topic and --rubric arguments in the omx command.
  • Boundary markers: The skill does not explicitly define delimiters or 'ignore' instructions for the processed data.
  • Capability inventory: The skill's capabilities are limited to executing omx subcommands and interacting with specific Codex goal tools (get_goal, create_goal, update_goal).
  • Sanitization: No sanitization or validation logic for the provided topic or rubric strings is mentioned in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
May 6, 2026, 05:06 PM