verify
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill is designed to run repository-specific verification commands (gates) such as linters, type checkers, and tests. These commands are detected deterministically from
package.json,Makefile, and CI configuration files byscripts/detect-gates.mjs. The skill also executes peer CLI agents (claudeorcodex) for cross-verification usingscripts/peer-run.mjs, employing strict security flags like--sandbox read-onlyand--permission-mode planto ensure these secondary agents cannot modify the system. - [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it processes untrusted data from the repository being analyzed (e.g., source code, commit history, and implementation plans).
- Ingestion points: Untrusted data enters the agent context through file reads in
detect-gates.mjs(parsing manifests and CI workflows) andworkflows/verify.mjs(reading repository files, plans, and git diffs). - Boundary markers: The workflow uses structured 'briefs' to isolate the context provided to sub-agents. A skeptical 'Judging' phase is explicitly designed to refute potentially biased or malicious findings injected into the review process.
- Capability inventory: The skill uses
execFileSyncandspawnto run detected repository gates and peer CLIs. It uses the platform'sagent()tool for reasoning and utilizesisolation: 'worktree'to perform behavioral proofs in a temporary git environment. - Sanitization:
scripts/forbidden-repairs.mjsprovides a deterministic regex-based guard that scans diffs created during the fix loop to prevent the automated insertion of test skips or type suppressions. - [DYNAMIC_EXECUTION]: The skill dynamically executes commands detected from the repository environment to fulfill its verification purpose. Behavioral proofs (Lane D) execute the actual software (starting servers or running CLIs) in an isolated git worktree, preventing permanent changes to the user's primary working directory during testing.
Audit Metadata