verification-loop
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and reviews content from the local file system, including source code, build logs, and test outputs. Malicious instructions embedded within these files could attempt to influence the agent's behavior during the review process.\n
- Ingestion points: Repository source code (read via
grep), version control data (read viagit diff), and process outputs from various build, lint, and test tools.\n - Boundary markers: There are no explicit delimiters or boundary markers defined in the instructions to isolate the untrusted code content from the agent's analytical logic.\n
- Capability inventory: The skill instructs the agent to execute a variety of shell-based development tools including
npm,make,cargo, andpytest.\n - Sanitization: The skill does not implement sanitization or validation of the external tool outputs or file contents before they are processed by the agent.
Audit Metadata