springboot-verification
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill implements a standard software development verification loop for Spring Boot projects using official build systems (Maven and Gradle) and established security plugins.
- [INDIRECT_PROMPT_INJECTION]: The skill processes local command outputs and source code diffs. 1. Ingestion points: Command outputs from mvn, gradle, and git in SKILL.md. 2. Boundary markers: The skill provides an output template but lacks specific delimiters to separate untrusted data from instructions. 3. Capability inventory: Execution of build commands (mvn, gradlew) and file system reads/writes in the target/build directories. 4. Sanitization: No explicit sanitization or filtering of external content is present. This ingestion is limited to local development and is required for the intended purpose of code verification.
Audit Metadata