maintain-app-verifier

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and reconcile data from local source code and "live evidence" files. Maliciously crafted content within these audited files could potentially influence the agent's behavior during the drift correction process.
  • Ingestion points: The agent reads the project-local feature index, source code, and live evidence files (referenced in SKILL.md).
  • Boundary markers: No explicit boundary markers or delimiters are specified to separate audited data from the agent's internal instructions.
  • Capability inventory: The skill allows the agent to modify project-local files to fix drift in maps, instructions, and verifier drivers (referenced in SKILL.md).
  • Sanitization: There are no instructions for sanitizing or validating the content extracted from the source files or live evidence.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 06:02 PM
Security Audit — agent-trust-hub — maintain-app-verifier