factory-verify

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill reads from documentation files docs/factory/CONTRACT.md and docs/factory/CHARTER.md to guide its verification process. These files serve as ingestion points for untrusted data that lacks boundary markers or sanitization, posing a risk of indirect prompt injection. 1. Ingestion points: docs/factory/CONTRACT.md, docs/factory/CHARTER.md. 2. Boundary markers: Absent. 3. Capability inventory: Execution of .factory/scripts/prove-test.sh. 4. Sanitization: Absent.
  • [COMMAND_EXECUTION]: The skill is instructed to run a local shell script .factory/scripts/prove-test.sh to provide negative test proof during PR verification.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 11:41 PM
Security Audit — agent-trust-hub — factory-verify