verification-protocols
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- Local Script Execution: The skill instructs the agent to run project-specific scripts such as
./tools/reorganize-headers/run.pyand./build.sh. While these execute commands in the local environment, they are standard components of the C++ development pipeline described in the skill. - Indirect Prompt Injection Surface: The formatting tool accepts a
<target>argument. In scenarios where this target is derived from untrusted external input (such as a pull request or user-provided filename), there is a potential surface for indirect prompt injection or command argument manipulation. However, given the developer-focused context and the use of standard project scripts, this is a common pattern in build automation tools. - Compilation and Testing: The skill includes steps to compile code and run test binaries. These are routine tasks for C++ verification and do not involve remote code retrieval or unexpected privilege changes.
Audit Metadata