verify
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill is designed to execute local shell scripts, specifically
./scripts/verify.sh, to run linting, type-checking, and tests as part of its verification process. This is the primary function of the skill within its software development context. - [INDIRECT_PROMPT_INJECTION]: The skill reads and processes content from project specification files (e.g.,
02-DOCS/wiki/sdd/specs/*.md) and task plans to verify completion. This ingestion of external data could allow malicious instructions embedded in those files to influence the agent's behavior if the repository content is untrusted. - Ingestion points: Specification files (
02-DOCS/wiki/sdd/specs/*.md), planning files (02-DOCS/wiki/sdd/plans/*.md), and the output of executed stack scripts (./scripts/verify.sh). - Boundary markers: None explicitly defined to isolate processed file content from the agent's internal instruction flow.
- Capability inventory: Execution of shell commands (subprocess calls) and writing files to the documentation directory (
02-DOCS/wiki/sdd/verifications/). - Sanitization: No evidence of sanitization or escaping of the ingested file content before it is processed by the agent.
Audit Metadata