verification-contract

Pass

Audited by Gen Agent Trust Hub on Aug 9, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill directs the agent to run "project commands" listed in ACCEPTANCE.md files to verify requirements.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes instructions and commands from external ACCEPTANCE.md files.
  • Ingestion points: Files located at /ACCEPTANCE.md.
  • Boundary markers: None explicitly defined in the skill instructions to separate project data from instructions.
  • Capability inventory: Shell command execution and Git operations (e.g., git hash-object).
  • Sanitization: The skill relies on cryptographic hashing to ensure the integrity of the input files rather than performing content-level sanitization.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 9, 2026, 09:48 PM
Security Audit — agent-trust-hub — verification-contract