verification-loop
Pass
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands for building, linting, and testing (e.g.,
npm run build,pnpm build,ruff check .). These commands execute logic defined in local project configuration files (likepackage.jsonorpyproject.toml), which could be compromised in untrusted repositories. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests output from various external tools into the agent's context to generate a verification report.
- Ingestion points: Tool outputs from
npm,pnpm,npx,pyright,ruff,grep, andgitare read and processed by the agent. - Boundary markers: Absent; the skill does not use delimiters or specific instructions to isolate untrusted tool output from the agent's instructions.
- Capability inventory: The agent has shell access to execute build systems, test runners, and git operations.
- Sanitization: No sanitization, escaping, or validation of the ingested tool output is performed before it is incorporated into the final report.
- [EXTERNAL_DOWNLOADS]: The use of
npx tscmay trigger a download of the TypeScript compiler from the public npm registry if it is not already installed in the local environment.
Audit Metadata