goal-framing — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited goal-framing (Agent Skill) and scored it 45/100 (orange). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 2 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 2 flagged
A base64 string of 128+ characters appears in a documentation file. Encoded prompt injection hides the hostile instruction in base64 — invisible to keyword filters — and relies on the agent's ability to decode it at runtime. There is no normal authoring reason to embed a multi-hundred-byte base64 blob in skill docs.
*.sig, SIGNATURES) outside the documentation.A base64 string of 128+ characters appears in a documentation file. Encoded prompt injection hides the hostile instruction in base64 — invisible to keyword filters — and relies on the agent's ability to decode it at runtime. There is no normal authoring reason to embed a multi-hundred-byte base64 blob in skill docs.
*.sig, SIGNATURES) outside the documentation.Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Use this skill to create a thin goal frame before execution. It is opt-in and boundary-setting only.
Do not use it for tiny edits, one-command checks, or ordinary fast-path Q&A unless the user explicitly asks for /aegis-goal or Aegis goal:.
Current owner:
Not owned here:
GateDecisionTreat these as equivalent:
/aegis-goal <task description>Aegis goal: <task description>Slash commands are optional host shortcuts. The natural-language form is the portable fallback.
Example:
Aegis goal: Fix the auth refresh bug without rewriting the auth system.Produce the smallest useful frame, then continue into the routed workflow in the same turn.
TaskIntentDraft:
- Requested outcome:
- Goal:
- Success evidence:
- Stop condition:
- Non-goals:
- Constraints:
- Scope:
- Risk hints:
- Route:
- Next:Default behavior:
TaskIntentDraft.Next action for the selectedroute when the user asked to do the work.
large internal-looking card unless the user asked for a formal frame.
Frame-only behavior:
only define the stop condition, not execute, not implement, not write a plan, or wait for confirmation before continuing.
blocked rather than pretending to continue.
Stop condition must distinguish:
State set: done, blocked, needs-verification, scope-exceeded.
done: success evidence is satisfiedblocked: required dependency, permission, or information is missingneeds-verification: implementation exists but evidence is insufficientscope-exceeded: continuing would exceed the goal or non-goalsAfter framing:
brainstormingwriting-planslong-task-continuation
systematic-debugging| Goal signal | Route |
|---|---|
| single-owner, low-risk, clear verification | fast path or test-driven-development |
| bug, failure, regression, unexpected behavior | systematic-debugging |
| ambiguous product, architecture, contract, cross-module behavior | brainstorming |
| approved spec, stable requirements, implementation slicing | writing-plans |
| multi-step, compaction-prone, handoff, subagent work | long-task-continuation |
| completion, release, handoff, "is this done?" | verification-before-completion |
Only create docs/aegis/ records when the routed workflow needs persistent evidence. Goal framing alone does not create project files.
When delegating work, pass a compact packet instead of the full conversation:
SubagentContextPacket:
- Task:
- Goal:
- Stop condition:
- Relevant baseline refs:
- Relevant files:
- Known facts:
- Unknowns:
- Non-goals:
- Expected output:
- Verification expected:
- Must-read excerpts:
- Unsafe assumptions:The packet reduces repeated file reading, but it does not replace evidence. Subagents should still read the smallest raw file/log/test excerpt needed to verify critical facts.
Do not paste full chat transcripts, full session history, or unbounded logs into the packet. If a fact matters, include a file ref, line/window hint, or compact must-read excerpt.
If the goal changes mid-task, do not silently overwrite it. Record old goal, new goal, changed scope, new risks, and route through DriftCheckDraft when a long-task record exists.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.