config-fails-open-verify-artifact

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes shell script examples that use grep, awk, find, and plutil. These tools are used for inspecting local configuration files (e.g., conveyor.conf) and application metadata (e.g., Info.plist in .app bundles) to verify build results.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines patterns for processing local file content. This constitutes a data ingestion surface, but it is limited to local developer-controlled files and does not interpolate untrusted remote data into dangerous capabilities.
  • [SAFE]: Analysis of the instructions and scripts reveals no network operations, credential harvesting, persistence mechanisms, or obfuscation. The content is educational and focuses on build pipeline assertions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 07:02 AM
Security Audit — agent-trust-hub — config-fails-open-verify-artifact