verification-before-completion
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists solely of Markdown and JSON metadata. It does not include any executable scripts, binaries, or automated network commands. It relies on the agent's host capabilities to execute verification tools specified by the user.- [PROMPT_INJECTION]: The instructions establish a rigorous 'Iron Law' for task completion. This is a behavioral framework designed to improve reliability and does not attempt to bypass agent safety filters or override system-level constraints.- [DATA_EXFILTRATION]: All URLs point to public source repositories on GitHub or the author's official domain (shipshit.dev). There are no indications of unauthorized data transmission or secret exfiltration patterns.- [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to evaluate external data such as test logs and version control diffs. While these are ingestion points for potentially untrusted data, the skill provides a logic for validation rather than an exploitable vulnerability. Ingestion points include command outputs and VCS diffs as described in SKILL.md; no explicit boundary markers or sanitization logic are defined in these instructions.
Audit Metadata