skills/ericrisco/rsc-harness/verify/Gen Agent Trust Hub

verify

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill is designed to execute local shell scripts, specifically ./scripts/verify.sh, to run linting, type-checking, and tests as part of its verification process. This is the primary function of the skill within its software development context.
  • [INDIRECT_PROMPT_INJECTION]: The skill reads and processes content from project specification files (e.g., 02-DOCS/wiki/sdd/specs/*.md) and task plans to verify completion. This ingestion of external data could allow malicious instructions embedded in those files to influence the agent's behavior if the repository content is untrusted.
  • Ingestion points: Specification files (02-DOCS/wiki/sdd/specs/*.md), planning files (02-DOCS/wiki/sdd/plans/*.md), and the output of executed stack scripts (./scripts/verify.sh).
  • Boundary markers: None explicitly defined to isolate processed file content from the agent's internal instruction flow.
  • Capability inventory: Execution of shell commands (subprocess calls) and writing files to the documentation directory (02-DOCS/wiki/sdd/verifications/).
  • Sanitization: No evidence of sanitization or escaping of the ingested file content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 11:11 PM
Security Audit — agent-trust-hub — verify