verify-plan

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external implementation plans, acceptance criteria, and repository content which could potentially contain malicious instructions.
  • Ingestion points: Acceptance Criteria, MECE Review, and Verification Plan sections extracted from the task context and repository (Step 1).
  • Boundary markers: The workflow mandates a strict structural schema (Step 1) for all input sections, which serves as a validation mechanism against unstructured or malformed injection attempts.
  • Capability inventory: The agent can execute repository scripts, database queries, and interact with rendered UI interfaces (Step 3, 4).
  • Sanitization: The instructions explicitly include guardrails, such as "Do not report sensitive contents" (Step 2) and a requirement that external mutations must be explicitly authorized by the live request (Step 10).
  • [COMMAND_EXECUTION]: The skill involves the execution of local repository tests and scripts as part of its primary verification function.
  • Evidence: Steps 3 and 4 instruct the agent to resolve direct observations using repository scripts, tests, and APIs.
  • Context: This activity is governed by a requirement to use existing mechanisms where possible and to verify that the repository state remains consistent via deterministic fingerprints (Step 2, 10), minimizing the risk of unauthorized command execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 10:32 AM
Security Audit — agent-trust-hub — verify-plan