skills/maxgfr/skills/verify/Gen Agent Trust Hub

verify

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill is designed to run repository-specific verification commands (gates) such as linters, type checkers, and tests. These commands are detected deterministically from package.json, Makefile, and CI configuration files by scripts/detect-gates.mjs. The skill also executes peer CLI agents (claude or codex) for cross-verification using scripts/peer-run.mjs, employing strict security flags like --sandbox read-only and --permission-mode plan to ensure these secondary agents cannot modify the system.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it processes untrusted data from the repository being analyzed (e.g., source code, commit history, and implementation plans).
  • Ingestion points: Untrusted data enters the agent context through file reads in detect-gates.mjs (parsing manifests and CI workflows) and workflows/verify.mjs (reading repository files, plans, and git diffs).
  • Boundary markers: The workflow uses structured 'briefs' to isolate the context provided to sub-agents. A skeptical 'Judging' phase is explicitly designed to refute potentially biased or malicious findings injected into the review process.
  • Capability inventory: The skill uses execFileSync and spawn to run detected repository gates and peer CLIs. It uses the platform's agent() tool for reasoning and utilizes isolation: 'worktree' to perform behavioral proofs in a temporary git environment.
  • Sanitization: scripts/forbidden-repairs.mjs provides a deterministic regex-based guard that scans diffs created during the fix loop to prevent the automated insertion of test skips or type suppressions.
  • [DYNAMIC_EXECUTION]: The skill dynamically executes commands detected from the repository environment to fulfill its verification purpose. Behavioral proofs (Lane D) execute the actual software (starting servers or running CLIs) in an isolated git worktree, preventing permanent changes to the user's primary working directory during testing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 06:03 AM
Security Audit — agent-trust-hub — verify