spring-boot
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The
scripts/verify.shutility performs local static analysis by executing standard shell commands such asgrepandsed. It is designed to identify legacy Spring Boot idioms in a project's source code and configuration files, operating exclusively on the local file system without network activity.\n- [PROMPT_INJECTION]: The skill processes user-supplied business requirements to generate Java backend code, creating an indirect prompt injection surface.\n - Ingestion points: User-provided specifications for REST endpoints, JPA entities, and security policies described in
SKILL.mdandevals/cases.yaml.\n - Boundary markers: Absent. The skill does not instruct the agent to use specific delimiters or ignore instructions embedded within user requirements.\n
- Capability inventory: The agent can generate and write
.java,.yml, and.sqlfiles, and execute the providedverify.shscript.\n - Sanitization: The skill lacks explicit instructions for sanitizing or validating the content of user-provided requirements before their inclusion in the generated code or configuration.
Audit Metadata