verification-loop

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands for building, linting, and testing (e.g., npm run build, pnpm build, ruff check .). These commands execute logic defined in local project configuration files (like package.json or pyproject.toml), which could be compromised in untrusted repositories.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests output from various external tools into the agent's context to generate a verification report.
  • Ingestion points: Tool outputs from npm, pnpm, npx, pyright, ruff, grep, and git are read and processed by the agent.
  • Boundary markers: Absent; the skill does not use delimiters or specific instructions to isolate untrusted tool output from the agent's instructions.
  • Capability inventory: The agent has shell access to execute build systems, test runners, and git operations.
  • Sanitization: No sanitization, escaping, or validation of the ingested tool output is performed before it is incorporated into the final report.
  • [EXTERNAL_DOWNLOADS]: The use of npx tsc may trigger a download of the TypeScript compiler from the public npm registry if it is not already installed in the local environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 03:43 AM
Security Audit — agent-trust-hub — verification-loop