work-check
Pass
Audited by Gen Agent Trust Hub on Jun 14, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes standard development oracles such as build, test, and lint commands, and executes applications locally to verify behavior. These operations are consistent with the skill's stated purpose of verifying code changes.
- [PROMPT_INJECTION]: To mitigate risks of instruction override, the skill mandates a schema-validated JSON 'Structured Result Contract' and a 'PASS-validity gate.' This ensures verdicts are derived from captured tool evidence rather than potentially influenced model reasoning.
- [DATA_EXFILTRATION]: The skill processes local repository information including git diffs and source code. No evidence of unauthorized network transmission or exfiltration to external domains was detected.
- [SAFE]: The workflow incorporates security-conscious design principles, such as prioritizing direct oracles and requiring independent source re-reading, which align with established best practices for agentic verification.
Audit Metadata