completion-check

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use standard tools like grep, ls, and ast-grep to verify that infrastructure components are correctly wired into the project. These commands are executed locally within the project scope to audit source code and configuration.
  • [INDIRECT_PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by directing the agent to read and analyze local source code, configuration files (.claude/settings.json), and temporary debug logs (/tmp/debug.log). 1. Ingestion points: Project source files in src/, local settings in .claude/, and debug logs in /tmp/. 2. Boundary markers: No explicit delimiters or warnings to ignore embedded instructions are provided for the ingested data. 3. Capability inventory: Includes file reading (grep, cat), local command execution (uv run), and file modification (echo >>). 4. Sanitization: No sanitization of the analyzed file content is specified, which is common for code verification tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:10 PM
Security Audit — agent-trust-hub — completion-check