guide-and-verify
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill's instructions focus on operational methodology and do not contain patterns intended to bypass AI safety filters or override core instructions. The language is purely instructional and aimed at improving agent accuracy during human-in-the-loop tasks.
- [DATA_EXPOSURE]: No hardcoded credentials, sensitive file paths, or network exfiltration patterns were found. The skill advises agents to take snapshots of system state for verification purposes but instructs to save them in persistent, project-appropriate locations like tickets or commits, which is a standard operational practice.
- [PRIVILEGE_ESCALATION]: The skill explicitly instructs the agent to respect access boundaries and avoid unauthorized access, stating "Do not quietly widen your access to finish it."
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process user descriptions of UI tasks to generate runbooks. The surface area for exploitation is limited as the skill generates text instructions for humans rather than executing automated commands. It mitigates risks by emphasizing read-only checks and explicit boundary declarations.
- [OBFUSCATION]: A thorough scan for Base64 encoding, zero-width characters, homoglyphs, and hidden text patterns revealed no attempts to hide malicious content or URLs.
Audit Metadata