maintain-verification-skill

Pass

Audited by Gen Agent Trust Hub on Aug 9, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted project data (source code and feature maps) to generate verification recipes and drive application sessions. \n
  • Ingestion points: Reads project-local source files and verification skill maps (e.g., in .cursor/skills/verify-*/). \n
  • Boundary markers: Lacks explicit delimiters or instructions to ignore embedded commands within the processed project files. \n
  • Capability inventory: Capable of writing to the verification skill directory, executing harness scripts, and launching subagents for analysis. \n
  • Sanitization: No evidence of sanitization or validation of the ingested content before it influences agent actions. \n- [COMMAND_EXECUTION]: The skill's 'Live pass' logic involves executing harness scripts and driving the target application's runtime (CLI, Server, or UI). While this is the intended functionality, it executes commands influenced by the audited project's state.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 9, 2026, 03:06 PM
Security Audit — agent-trust-hub — maintain-verification-skill