maintain-verification-skill

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill presents an indirect prompt injection surface by ingesting untrusted project files.
  • Ingestion points: Reads feature map files and source code entry points (SKILL.md).
  • Boundary markers: Absent; no markers or instructions to disregard embedded content were found.
  • Capability inventory: The skill can modify project files and execute local harness scripts (SKILL.md).
  • Sanitization: Absent; no input validation or sanitization is specified for ingested file content.
  • [COMMAND_EXECUTION]: The skill executes local harness scripts to perform live verification of application features.
  • Evidence: Step 4 ('Live pass') describes driving the application and exercising features using the verification skill's launch model (SKILL.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 08:47 PM
Security Audit — agent-trust-hub — maintain-verification-skill