verify-trend-report
Pass
Audited by Gen Agent Trust Hub on Jul 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
Bashtool to execute a local discovery script (discover-projects.sh) within the plugin's installation directory to identify project folders. It also performs standard file operations like backups and versioning usingcpcommands. - [PROMPT_INJECTION]: The skill processes user-provided or synthesized report content, representing an indirect prompt injection surface.
- Ingestion points: Untrusted content is ingested from
tips-trend-report.mdandtips-trend-report-claims.jsonduring the discovery and verification phases. - Boundary markers: No explicit delimiters or boundary markers are defined in the instructions for the content of the report files.
- Capability inventory: The skill possesses
Bashexecution,Writeaccess to the filesystem, and the ability to trigger other specialized skills (cogni-claims,cogni-copywriting,cogni-visual). - Sanitization: No explicit sanitization or filtering of the report's markdown content is described before processing by sub-agents.
Audit Metadata