skills/security-phoenix-demo/security-skills-claude-code/phoenix-verification-matrix/Gen Agent Trust Hub
phoenix-verification-matrix
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill defines a formal process for verification planning within a security spec pipeline. It operates solely on requirement definitions to produce a Markdown-based test matrix. No malicious patterns, data exfiltration, or unauthorized command execution risks were identified.
- [INDIRECT_PROMPT_INJECTION]: The skill represents a low-risk ingestion surface as it processes requirement statements from external sources (Roles 04, 06, and 07). However, the skill lacks high-privilege capabilities such as file system writes, network requests, or code execution, rendering the surface non-exploitable.
- Ingestion points: External requirement statements from Roles 04, 06, and 07 are ingested to be mapped to proof methods.
- Boundary markers: Not explicitly defined in the instruction set.
- Capability inventory: None detected. The skill only generates a Markdown output table.
- Sanitization: Not explicitly defined, though the skill itself mandates the creation of tests for prompt injection sanitization in the projects it analyzes.
Audit Metadata