discovering-vendor-behavior

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides guidance on using network tools like curl and writing short scripts to probe sandbox URLs. These actions are intended for measuring vendor behavior and are consistent with the skill's primary purpose.
  • [SAFE]: The skill utilizes vendor-specific infrastructure, including control URLs and credentials managed through /veris/* endpoints. This is standard functionality for the Veris-ai ecosystem.
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of data from external sandbox environments to verify vendor claims, creating a potential surface for indirect injection if sandbox responses are untrusted.
  • Ingestion points: Accessing data from /veris/manual, /veris/schema, and /veris/requests via the sandbox control_url.
  • Boundary markers: No explicit markers or delimiters are defined for isolating data retrieved from sandbox endpoints.
  • Capability inventory: File system writes to .veris/MEASUREMENTS.md and shell command execution for probe requests.
  • Sanitization: No specific sanitization or validation protocols are described for the content returned by the sandbox environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 12:55 PM
Security Audit — agent-trust-hub — discovering-vendor-behavior