maintain-verification-skill
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill reads and processes untrusted project files, including source code and feature maps. Ingestion points: Reads project-local verification skills and feature maps (SKILL.md Pass 0), and product source code (SKILL.md Pass 2). Boundary markers: None identified; there are no instructions to use delimiters or ignore instructions within the source files. Capability inventory: The skill can modify the verification skill directory, open Pull Requests, and execute local app instances (SKILL.md Contract). Sanitization: No validation or sanitization of ingested content is specified.
- [COMMAND_EXECUTION]: The skill executes local code as part of its verification process. Evidence: SKILL.md specifies that it starts and tears down local app instances during the 'live pass' phase.
Audit Metadata