skills/openai/plugins/verify-fix/Gen Agent Trust Hub

verify-fix

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [Indirect Prompt Injection Surface]: The skill is designed to ingest and process external security findings, which serves as a potential vector for instructions embedded within data to influence the agent.
  • Ingestion points: The skill processes "supplied security findings" and "finding-or-issue-id" as primary inputs (SKILL.md).
  • Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands within the processed findings.
  • Capability inventory: The skill is authorized to perform repository inspection and "run the original reproducer" or "regression checks" (SKILL.md).
  • Sanitization: There are no explicit requirements to sanitize or validate the source or content of the findings before they are analyzed.
  • [Runtime Execution Consideration]: The workflow involves running original reproducers to verify remediation. If these reproducers are provided as part of an untrusted finding, they could result in the execution of unintended logic. The skill includes safety instructions to operate in "standalone verification-only mode" and to avoid repository modifications, which helps mitigate risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 11:46 AM
Security Audit — agent-trust-hub — verify-fix