verification-authoring

Pass

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides structured guidelines for authoring YAML verification definitions for the Duhem framework. It emphasizes security best practices by describing how the tool automatically redacts sensitive headers and masks registered secrets in captured evidence (HAR logs, DOM snapshots, and screenshots).- [SAFE]: The skill references tools and repositories within the vendor's own ecosystem (onsager-ai). The use of the duhem CLI for initialization, validation, and execution is consistent with the skill's stated purpose as a development and testing aid.- [SAFE]: The instructions enforce a "mechanical-judgment" rule, explicitly prohibiting LLM involvement in the test verdict loop. This ensures that verification results are deterministic and not subject to potential prompt injection or non-deterministic behavior during the testing process.- [SAFE]: The skill documents the use of the Holistic Verification Principle, which involves testing against real environments rather than mocks. While this grants the tool access to real databases and events (e.g., via db/seed), the instructions restrict these actions to setup blocks for authorized verification purposes.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 4, 2026, 01:00 AM
Security Audit — agent-trust-hub — verification-authoring