verification-before-completion
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill employs highly authoritative language, such as "The Iron Law" and "Non-negotiable," and issues threats like "If you lie, you'll be replaced." These are intended to enforce a strict quality-control workflow and do not appear to be attempts to bypass safety filters or ignore ethical constraints.
- [INDIRECT_PROMPT_INJECTION]: The skill requires the agent to execute shell commands and read the resulting full output (e.g., test results, build logs, linter errors) to verify success claims. This ingestion of untrusted external data establishes a surface for indirect prompt injection. 1. Ingestion points: Full command output from verification tools (SKILL.md). 2. Boundary markers: Absent; no delimiters are defined for the tool output. 3. Capability inventory: General shell command execution via agent tools. 4. Sanitization: Absent; no validation or filtering of the ingested logs is specified.
- [NO_CODE]: This skill consists entirely of markdown instructions and YAML metadata without any accompanying scripts, executables, or code files.
Audit Metadata