deliverable-validator

Pass

Audited by Gen Agent Trust Hub on Mar 16, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill presents a surface for indirect prompt injection and includes self-referential safety claims. 1. Ingestion points: Acceptance criteria documents, user requirements, and test results (SKILL.md). 2. Boundary markers: The instructions do not define delimiters to separate agent instructions from untrusted external data. 3. Capability inventory: The workflow involves executing unspecified validation checks and capturing evidence outputs (SKILL.md). 4. Sanitization: No input filtering, escaping, or validation of processed data is described. Additionally, the skill contains the self-referential claim 'No security warnings' within its quality validation criteria.
  • [NO_CODE]: The skill consists entirely of Markdown and YAML-formatted instructions and templates. It does not provide any executable scripts, binaries, or runtime configuration.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 16, 2026, 02:20 AM