config-fails-open-verify-artifact
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill includes shell script examples that use
grep,awk,find, andplutil. These tools are used for inspecting local configuration files (e.g.,conveyor.conf) and application metadata (e.g.,Info.plistin.appbundles) to verify build results. - [INDIRECT_PROMPT_INJECTION]: The skill defines patterns for processing local file content. This constitutes a data ingestion surface, but it is limited to local developer-controlled files and does not interpolate untrusted remote data into dangerous capabilities.
- [SAFE]: Analysis of the instructions and scripts reveals no network operations, credential harvesting, persistence mechanisms, or obfuscation. The content is educational and focuses on build pipeline assertions.
Audit Metadata