verification-before-completion

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill consists entirely of markdown instructions without any accompanying scripts, executables, or configuration files.
  • [INDIRECT_PROMPT_INJECTION]: The skill outlines a workflow that ingests untrusted data from tool outputs. 1. Ingestion points: The agent is instructed to read full output from verification commands (e.g., tests, linters, builds) in SKILL.md. 2. Boundary markers: The skill does not define specific delimiters or 'ignore' warnings for the command output. 3. Capability inventory: The skill itself has no code, but is designed for an agent environment that can execute shell commands and modify version control. 4. Sanitization: No sanitization or filtering of the command output is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 11:04 AM
Security Audit — agent-trust-hub — verification-before-completion