verify
Pass
Audited by Gen Agent Trust Hub on Jun 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes standard development tools including ruff and pytest, as well as a local script located at scripts/fetch_vendor.py to verify project integrity. These operations are routine for software development environments.
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface because it processes and reports tool output from code that could be attacker-controlled. Ingestion points: Command output from ruff and pytest. Boundary markers: Absent. Capability inventory: Local command execution. Sanitization: Absent.
Audit Metadata