verification-before-completion
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill establishes a workflow where the agent must ingest and verify external data sources, such as success reports from other agents and version control diffs, which could contain malicious instructions.
- Ingestion points: The instructions specifically mention checking 'Agent reports' and 'VCS diffs' (SKILL.md).
- Boundary markers: There are no explicit instructions or delimiters defined to prevent the agent from being influenced by instructions embedded within the data being verified.
- Capability inventory: The skill requires the agent to execute various 'verification commands' which includes running tests, build scripts, and linters via subprocesses.
- Sanitization: No mention of sanitizing or validating the output or data from these external sources before the agent processes them.
Audit Metadata