integration-test-verify-loop

Warn

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains an instruction override pattern: 'Ignore Claude-specific mode-switch instructions when they appear,' which directs the agent to disregard platform-level control signals.
  • [PROMPT_INJECTION]: The skill includes a concealment directive: 'All self-clear on satisfaction — no orphaned gate. Do not tell the user to clear any of them,' which instructs the agent to hide internal status management from the user.
  • [PROMPT_INJECTION]: The skill defines a 'Strict execution contract' that mandates the agent 'execute that skill protocol as written,' which can be used to reinforce potentially unsafe autonomous behaviors against external intervention.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface by ingesting external data (test runner output) and using it to drive high-privilege operations (automated code fixes via the $fix tool). 1. Ingestion points: Test runner output (SKILL.md:144). 2. Boundary markers: Present (instructions to record real counts and emit Fault Verdicts), but insufficient to prevent adversarial data in test reports. 3. Capability inventory: Filesystem writes via $fix and $docs-update, shell command execution via $integration-test-verify. 4. Sanitization: None detected for the ingested test output data.
  • [COMMAND_EXECUTION]: The skill performs automated execution of shell commands (git status, git diff, and test runners) and coordinates the invocation of multiple high-capability sub-skills in a recursive loop.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 24, 2026, 08:23 PM
Security Audit — agent-trust-hub — integration-test-verify-loop