goap-agent

Pass

Audited by Gen Agent Trust Hub on Mar 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes standard shell commands such as ls and grep to manage project-specific architectural records and build tools like cargo for code quality validation. These operations are scoped to the local development environment.
  • [PROMPT_INJECTION]: As an orchestration skill, it processes data from external research and local files, creating a surface for indirect prompt injection. Ingestion points: Architectural Decision Records (ADRs) and outputs from research tools like web-search-researcher. Boundary markers: Implementation of mandatory 'Quality Gates' and sequential phases to isolate task outputs. Capability inventory: Uses Bash, Read, Write, and Edit tools. Sanitization: Employs specialized validation agents like code-reviewer and rust-code-quality to verify the safety and quality of outputs before proceeding.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 6, 2026, 12:26 PM