verify-gate
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection as it ingests and executes commands from untrusted project files.
- Ingestion points: The skill discovers commands by reading
CLAUDE.md,AGENTS.md,.github/copilot-instructions.md,package.json,Cargo.toml,pyproject.toml, and.verify-gate.ymlfrom the workspace. - Boundary markers: The skill does not employ delimiters or specific instructions to the agent to ignore or isolate potentially malicious code embedded within these project files.
- Capability inventory: The skill has the capability to execute arbitrary shell commands and JavaScript code via the agent's subprocess and script execution tools.
- Sanitization: There is no validation or sanitization performed on the discovered commands; the skill assumes all commands found in the specified locations are safe to execute.
- [COMMAND_EXECUTION]: The skill's core functionality relies on discovering and running shell commands (e.g.,
npm run,pytest,cargo test) from the environment, which can be exploited if the environment's configuration files are compromised. - [DYNAMIC_EXECUTION]: The
mcp-scriptsfeature facilitates the execution of arbitrary shell or JavaScript code defined at runtime within the project's configuration files.
Audit Metadata