app-verification
Pass
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill's primary function is the creation and execution of a verify CLI consisting of
doctor,seed, andverifycommands. These scripts are designed to interact directly with the host shell, package managers, and local databases to validate application state. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the repository, specifically within the
features/directory. TheDrivefield infeatures/*.mdfiles is interpreted as a shell command or test script to be executed by the agent. - Ingestion points: The agent reads and parses
features/*.mdfiles from the local project repository (specified inreferences/feature-map-format.md). - Boundary markers: No explicit boundary markers or warnings are used to instruct the agent to treat the
Drivefield as untrusted or to sanitize its contents. - Capability inventory: The skill allows for arbitrary shell command execution, file system writes, and network operations via the generated
verifyharness. - Sanitization: There is no evidence of sanitization, escaping, or validation of the commands extracted from the
Drivefield before they are executed. - [DYNAMIC_EXECUTION]: In 'Create' mode, the skill instructs the agent to scaffold new executable scripts (
doctor,seed,verify) in the target repository and then immediately execute them to 'prove the harness.' This involves writing code to the filesystem and running it at runtime.
Audit Metadata