ps-maintain-verification-skill

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes project source code and feature maps to verify application behavior and update test harnesses. This workflow creates an entry point where malicious instructions embedded in the analyzed code (such as in comments or strings) could influence the agent during the source analysis or reconciliation phases.\n- Ingestion points: The agent reads arbitrary files from the product source tree and files within the target verification skill directory.\n- Boundary markers: The instructions do not specify the use of delimiters or 'ignore' commands to isolate instructions that might be contained within the analyzed data.\n- Capability inventory: The skill is authorized to modify local files, execute local test harness scripts via subprocess calls, and create Pull Requests with findings.\n- Sanitization: There is no requirement for the agent to sanitize or escape content retrieved from external files before it is processed or merged into the skill directory.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 01:26 AM
Security Audit — agent-trust-hub — ps-maintain-verification-skill