verify-done
Pass
Audited by Gen Agent Trust Hub on Jul 11, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns, obfuscation, or unauthorized data access detected.
- [COMMAND_EXECUTION]: The skill instructs the agent to perform local verification tasks, such as running tests, linters, type checkers, and VCS commands (
git diff). It also references project-specific backlog tools (bd,dh). These operations are consistent with the skill's purpose as a developer tool and do not involve unauthorized privilege escalation or access to sensitive system files. - [PROMPT_INJECTION]: While the skill uses strong instructional language (e.g., "STOP. You are NOT done yet") and provides "authoritative" flowcharts to guide agent behavior, these are intended for quality control and task verification. There are no attempts to bypass safety filters, extract system prompts, or induce unrestricted behavior.
- [DATA_EXFILTRATION]: The skill requests that the agent provide evidence of task completion, such as pasting command outputs or test results. These actions remain within the session context and do not involve sending data to external or untrusted domains.
Audit Metadata