springboot-verification

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes command-line interfaces for Maven (mvn) and Gradle (./gradlew) to perform build, test, and static analysis tasks. It also uses grep and git to inspect project source code and repository history.
  • [EXTERNAL_DOWNLOADS]: Fetches the official postgres:16-alpine container image from Docker Hub for use in integration testing with Testcontainers. It also relies on standard package managers to resolve project dependencies from well-known registries.
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes untrusted data from the local project environment to generate verification reports.
  • Ingestion points: Ingests project source code files, test logs, and git diff output through scanning commands.
  • Boundary markers: Employs a structured Output Template to format the agent's summary and findings, providing a logical separation for reported data.
  • Capability inventory: Includes execution of shell commands (build tools) and file system read access for security scanning and diff reviews.
  • Sanitization: Relies on standard agent processing without explicit input escaping or sanitization of the content extracted from the analyzed files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:41 PM
Security Audit — agent-trust-hub — springboot-verification