verification-contract
Pass
Audited by Gen Agent Trust Hub on Aug 9, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill directs the agent to run "project commands" listed in ACCEPTANCE.md files to verify requirements.
- [INDIRECT_PROMPT_INJECTION]: The skill processes instructions and commands from external ACCEPTANCE.md files.
- Ingestion points: Files located at /ACCEPTANCE.md.
- Boundary markers: None explicitly defined in the skill instructions to separate project data from instructions.
- Capability inventory: Shell command execution and Git operations (e.g., git hash-object).
- Sanitization: The skill relies on cryptographic hashing to ensure the integrity of the input files rather than performing content-level sanitization.
Audit Metadata