runtime-verification-discipline

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill defines an 'Iron Law' requiring the AI agent to execute verification code within the runtime environment. It prioritizes project-specific scripts found via convention over generic tools.
  • [PROMPT_INJECTION]: The skill creates an attack surface for indirect prompt injection by directing the agent to automatically locate and execute project-level verification scripts. Ingestion points: 'Provider resolution' section in SKILL.md. Boundary markers: No explicit instructions to ignore embedded prompts in project scripts are provided. Capability inventory: 'Iron Law' mandates execution, and the provider resolution mechanism allows loading project skills. Sanitization: No sanitization of external project scripts is specified.
  • [COMMAND_EXECUTION]: The 'A — unwired automation' section instructs the agent to dynamically generate ('wire') and execute missing verification scripts at runtime.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 10:11 AM
Security Audit — agent-trust-hub — runtime-verification-discipline