gsd-verify-work
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection. It is designed to validate 'built features' and engage in 'conversational testing', which involves ingesting external, potentially untrusted data.\n
- Ingestion points: Untrusted content enters the agent's context through the reading of built feature files and user-provided test inputs.\n
- Boundary markers: The skill definition does not provide explicit delimiters or instructions to ignore embedded commands within the data being tested.\n
- Capability inventory: The skill has access to high-impact tools including
Bashfor command execution,EditandWritefor file system modification, andAgentfor delegating tasks.\n - Sanitization: No specific sanitization, filtering, or validation logic is defined in this configuration to prevent the execution of instructions embedded in the features under test.
Audit Metadata