verification-before-completion
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill uses high-pressure directive patterns, such as defining an 'Iron Law' and explicitly stating that variations are 'lying', to override an agent's standard reporting behavior. It also presents an indirect injection surface.
- Ingestion points: The agent reads and interprets the 'Full output' of verification commands (SKILL.md).
- Boundary markers: There are no delimiters or warnings to ignore malicious instructions embedded in the command output.
- Capability inventory: The skill authorizes the execution of arbitrary test, build, and linter commands.
- Sanitization: No escaping or validation of output content is performed before processing.
- [COMMAND_EXECUTION]: The workflow requires the agent to identify and run 'FULL' shell commands locally, granting it direct interaction with the system environment to generate verification logs.
Audit Metadata