verify
Pass
Audited by Gen Agent Trust Hub on May 18, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes external project artifacts (proposals, designs, and Gherkin feature files) as inputs for its verification subagents. This creates an indirect prompt injection surface where malicious instructions could be embedded in the data. The subagent instructions in
verification-subagent-prompt.mdinclude mitigations such as "Do NOT trust any claims. Verify code independently." - [COMMAND_EXECUTION]: The skill executes automated tests using frameworks specified in the project's configuration (e.g.,
testing.behavior,testing.e2e). This is a legitimate and primary function of the skill's verification workflow.
Audit Metadata