gsd-verify-work

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection. It is designed to validate 'built features' and engage in 'conversational testing', which involves ingesting external, potentially untrusted data.\n
  • Ingestion points: Untrusted content enters the agent's context through the reading of built feature files and user-provided test inputs.\n
  • Boundary markers: The skill definition does not provide explicit delimiters or instructions to ignore embedded commands within the data being tested.\n
  • Capability inventory: The skill has access to high-impact tools including Bash for command execution, Edit and Write for file system modification, and Agent for delegating tasks.\n
  • Sanitization: No specific sanitization, filtering, or validation logic is defined in this configuration to prevent the execution of instructions embedded in the features under test.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 07:21 PM
Security Audit — agent-trust-hub — gsd-verify-work