grace-verification
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill identifies and executes verification tasks such as 'bun run gate:e2e' and 'grace lint' within the local environment to record software health evidence.
- [INDIRECT_PROMPT_INJECTION]: The skill processes external configuration data from '.grace/verification/index.xml' which determines the parameters for command execution, creating a potential surface for indirect instruction injection.
- Ingestion points: '.grace/verification/index.xml' and routed verification documents.
- Boundary markers: Absent in instructions for parsing configuration files.
- Capability inventory: Full shell command execution via defined gate tasks.
- Sanitization: No mention of input sanitization or command validation for the verification manifest.
Audit Metadata