Security audit
Goal Command
Security checks for vulnerabilities and agentic risk
Overview
Goal Command appears aligned with its stated purpose, but it deliberately makes `/goal` keep the agent working and writes persistent notes, so users should invoke and configure it deliberately.
Install this if you want `/goal` to be an execution-oriented workflow, not just a planner. Keep goals scoped, review approvals for any destructive or external actions, choose the Obsidian sync path carefully, and remember that run files may persist goal text and session metadata.
Static analysis
No suspicious patterns detected.
