springboot-verification
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes command-line interfaces for Maven (
mvn) and Gradle (./gradlew) to perform build, test, and static analysis tasks. It also usesgrepandgitto inspect project source code and repository history. - [EXTERNAL_DOWNLOADS]: Fetches the official
postgres:16-alpinecontainer image from Docker Hub for use in integration testing with Testcontainers. It also relies on standard package managers to resolve project dependencies from well-known registries. - [INDIRECT_PROMPT_INJECTION]: The skill analyzes untrusted data from the local project environment to generate verification reports.
- Ingestion points: Ingests project source code files, test logs, and
git diffoutput through scanning commands. - Boundary markers: Employs a structured
Output Templateto format the agent's summary and findings, providing a logical separation for reported data. - Capability inventory: Includes execution of shell commands (build tools) and file system read access for security scanning and diff reviews.
- Sanitization: Relies on standard agent processing without explicit input escaping or sanitization of the content extracted from the analyzed files.
Audit Metadata