goap-agent
Pass
Audited by Gen Agent Trust Hub on Mar 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes standard shell commands such as
lsandgrepto manage project-specific architectural records and build tools likecargofor code quality validation. These operations are scoped to the local development environment. - [PROMPT_INJECTION]: As an orchestration skill, it processes data from external research and local files, creating a surface for indirect prompt injection. Ingestion points: Architectural Decision Records (ADRs) and outputs from research tools like
web-search-researcher. Boundary markers: Implementation of mandatory 'Quality Gates' and sequential phases to isolate task outputs. Capability inventory: UsesBash,Read,Write, andEdittools. Sanitization: Employs specialized validation agents likecode-reviewerandrust-code-qualityto verify the safety and quality of outputs before proceeding.
Audit Metadata