verification-loop

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill instructions facilitate standard software development quality gates such as building, type checking, and linting using established tools like npm, pnpm, tsc, pyright, and ruff. All shell commands are used for their intended diagnostic purposes.\n- [INDIRECT_PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by instructing the agent to process and report on potentially untrusted data from build logs and source code files.\n
  • Ingestion points: Output from build, lint, and test commands, and file contents from grep and git diff commands in SKILL.md.\n
  • Boundary markers: None defined to prevent the agent from misinterpreting instructions found within the logs or source code.\n
  • Capability inventory: Shell command execution for project analysis and build tasks.\n
  • Sanitization: None; tool outputs are processed and reported directly by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:41 PM
Security Audit — agent-trust-hub — verification-loop