verification-before-completion

Pass

Audited by Gen Agent Trust Hub on May 20, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a local script located at scripts/aegis-workspace.py within the target project's root. This is used for bundling work records and checking workspace integrity as part of the verification process. This is a standard operational procedure for developer-oriented skills and involves no remote downloads.
  • [PROMPT_INJECTION]: The skill is designed to ingest and process the output of verification commands. While this represents a surface for indirect prompt injection (where a command's output might contain instructions that influence the agent), the skill includes instructions to 'Verify: output confirms claim' and 'Confidence' grading, which serves as a manual checkpoint for the agent's logic. This is a low-risk surface inherent to verification tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
May 20, 2026, 06:00 AM
Security Audit — agent-trust-hub — verification-before-completion