factory-verify
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill reads from documentation files
docs/factory/CONTRACT.mdanddocs/factory/CHARTER.mdto guide its verification process. These files serve as ingestion points for untrusted data that lacks boundary markers or sanitization, posing a risk of indirect prompt injection. 1. Ingestion points: docs/factory/CONTRACT.md, docs/factory/CHARTER.md. 2. Boundary markers: Absent. 3. Capability inventory: Execution of.factory/scripts/prove-test.sh. 4. Sanitization: Absent. - [COMMAND_EXECUTION]: The skill is instructed to run a local shell script
.factory/scripts/prove-test.shto provide negative test proof during PR verification.
Audit Metadata