verify-gate

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection as it ingests and executes commands from untrusted project files.
  • Ingestion points: The skill discovers commands by reading CLAUDE.md, AGENTS.md, .github/copilot-instructions.md, package.json, Cargo.toml, pyproject.toml, and .verify-gate.yml from the workspace.
  • Boundary markers: The skill does not employ delimiters or specific instructions to the agent to ignore or isolate potentially malicious code embedded within these project files.
  • Capability inventory: The skill has the capability to execute arbitrary shell commands and JavaScript code via the agent's subprocess and script execution tools.
  • Sanitization: There is no validation or sanitization performed on the discovered commands; the skill assumes all commands found in the specified locations are safe to execute.
  • [COMMAND_EXECUTION]: The skill's core functionality relies on discovering and running shell commands (e.g., npm run, pytest, cargo test) from the environment, which can be exploited if the environment's configuration files are compromised.
  • [DYNAMIC_EXECUTION]: The mcp-scripts feature facilitates the execution of arbitrary shell or JavaScript code defined at runtime within the project's configuration files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 08:42 AM
Security Audit — agent-trust-hub — verify-gate