verification-before-completion
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill employs highly assertive and mandatory language, such as "The Iron Law" and statements that "Violating the letter of this rule is violating the spirit of this rule," to strictly govern agent behavior. While these linguistic patterns are often used in attempts to override system prompts, in this context, they are used to enforce a quality-control protocol for software development tasks rather than to bypass safety filters.
- [INDIRECT_PROMPT_INJECTION]: The skill mandates that the agent "READ: Full output" and "check exit code" for various commands. This behavior creates a surface for indirect prompt injection, as the agent is instructed to ingest potentially untrusted data from tool outputs. If a file or test output contains malicious instructions, the agent might be influenced by them while following this skill's verification requirements. The skill does not provide specific guidance on sanitizing or ignoring instructions embedded in these command outputs.
- [SAFE]: The skill is composed entirely of markdown instructions and does not include any scripts, executable code, network exfiltration patterns, or persistence mechanisms. It promotes a best-practice "evidence-first" approach to automated tasks.
Audit Metadata