validate-delivery
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from
task.descriptioninSKILL.mdto extract requirements using regular expressions. This extracted text is then used to determine the validation status and generate fix instructions without sanitization or boundary markers.\n - Ingestion points: The
task.descriptionfield is processed within theextractRequirementsfunction.\n - Boundary markers: No delimiters or instructions for the agent to ignore embedded commands are present in the parsing logic.\n
- Capability inventory: The skill has the ability to execute shell commands (
npm,pytest,cargo,go) and complete workflow phases based on validation results.\n - Sanitization: The requirements are extracted via regex and used directly in verification steps without any validation or escaping.\n- [COMMAND_EXECUTION]: The skill executes shell commands to perform builds and tests (e.g.,
npm test,pytest,cargo build). While these operations are fundamental to the skill's purpose of delivery validation, they constitute local command execution on the user's project files.
Audit Metadata