maintain-verification-skill

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill reads and processes untrusted project files, including source code and feature maps. Ingestion points: Reads project-local verification skills and feature maps (SKILL.md Pass 0), and product source code (SKILL.md Pass 2). Boundary markers: None identified; there are no instructions to use delimiters or ignore instructions within the source files. Capability inventory: The skill can modify the verification skill directory, open Pull Requests, and execute local app instances (SKILL.md Contract). Sanitization: No validation or sanitization of ingested content is specified.
  • [COMMAND_EXECUTION]: The skill executes local code as part of its verification process. Evidence: SKILL.md specifies that it starts and tears down local app instances during the 'live pass' phase.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 08:30 AM
Security Audit — agent-trust-hub — maintain-verification-skill