app-verification

Pass

Audited by Gen Agent Trust Hub on Oct 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill's primary function is the creation and execution of a verify CLI consisting of doctor, seed, and verify commands. These scripts are designed to interact directly with the host shell, package managers, and local databases to validate application state.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the repository, specifically within the features/ directory. The Drive field in features/*.md files is interpreted as a shell command or test script to be executed by the agent.
  • Ingestion points: The agent reads and parses features/*.md files from the local project repository (specified in references/feature-map-format.md).
  • Boundary markers: No explicit boundary markers or warnings are used to instruct the agent to treat the Drive field as untrusted or to sanitize its contents.
  • Capability inventory: The skill allows for arbitrary shell command execution, file system writes, and network operations via the generated verify harness.
  • Sanitization: There is no evidence of sanitization, escaping, or validation of the commands extracted from the Drive field before they are executed.
  • [DYNAMIC_EXECUTION]: In 'Create' mode, the skill instructs the agent to scaffold new executable scripts (doctor, seed, verify) in the target repository and then immediately execute them to 'prove the harness.' This involves writing code to the filesystem and running it at runtime.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 4, 2026, 03:50 PM
Security Audit — agent-trust-hub — app-verification