runtime-verification-discipline
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill defines an 'Iron Law' requiring the AI agent to execute verification code within the runtime environment. It prioritizes project-specific scripts found via convention over generic tools.
- [PROMPT_INJECTION]: The skill creates an attack surface for indirect prompt injection by directing the agent to automatically locate and execute project-level verification scripts. Ingestion points: 'Provider resolution' section in SKILL.md. Boundary markers: No explicit instructions to ignore embedded prompts in project scripts are provided. Capability inventory: 'Iron Law' mandates execution, and the provider resolution mechanism allows loading project skills. Sanitization: No sanitization of external project scripts is specified.
- [COMMAND_EXECUTION]: The 'A — unwired automation' section instructs the agent to dynamically generate ('wire') and execute missing verification scripts at runtime.
Audit Metadata