maintain-verification-skill

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted project data (source code and feature files) to determine how to drive a 'Live pass'. Malicious instructions embedded in these files could attempt to influence the execution logic or the content of the final pull request.
  • [COMMAND_EXECUTION]: The skill is designed to execute project-local 'harness scripts' and launch application instances as part of its verification routine. While this is intended behavior for its primary purpose, it requires the user to trust the scripts residing in the targeted verification skill's directory.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 06:20 AM
Security Audit — agent-trust-hub — maintain-verification-skill