validate-delivery

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from task.description in SKILL.md to extract requirements using regular expressions. This extracted text is then used to determine the validation status and generate fix instructions without sanitization or boundary markers.\n
  • Ingestion points: The task.description field is processed within the extractRequirements function.\n
  • Boundary markers: No delimiters or instructions for the agent to ignore embedded commands are present in the parsing logic.\n
  • Capability inventory: The skill has the ability to execute shell commands (npm, pytest, cargo, go) and complete workflow phases based on validation results.\n
  • Sanitization: The requirements are extracted via regex and used directly in verification steps without any validation or escaping.\n- [COMMAND_EXECUTION]: The skill executes shell commands to perform builds and tests (e.g., npm test, pytest, cargo build). While these operations are fundamental to the skill's purpose of delivery validation, they constitute local command execution on the user's project files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 07:15 AM
Security Audit — agent-trust-hub — validate-delivery