feature-verify

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is purpose-built for read-only runtime verification. It incorporates a dedicated 'Safety Rules & Endpoint Allowlist' policy that denies all operations by default and prohibits any state-mutating HTTP methods or database operations.
  • [COMMAND_EXECUTION]: Bash is utilized to perform health checks and API queries via curl. This is restricted to user-configured environments and endpoints, with behavioral guardrails ensuring one request at a time to prevent accidental load testing or abuse.
  • [EXTERNAL_DOWNLOADS]: The skill interacts with project-specific target APIs and logging backends as defined by the user in the 'environments.md' configuration. It does not download or execute scripts from unverified or unknown third-party sources.
  • [PROMPT_INJECTION]: While the skill ingests external data from API responses and logs, it mitigates risk via a mandatory 'Dual Verification' workflow. A second model (Codex) independently reviews all executed commands at the end of the session to confirm they adhered to the read-only allowlist and safety rules.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 01:44 PM
Security Audit — agent-trust-hub — feature-verify