verify-quality-performance
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to analyze external project components, creating a surface where malicious instructions could be embedded in the data being optimized.
- Ingestion points: According to the '验证证据' (Verification Evidence) section in
SKILL.md, the agent ingests external specifications, plans, source code, user feedback, and deployment context. - Boundary markers: The skill lacks explicit instructions or markers to delimit external content or to ignore potential commands embedded within the analyzed materials.
- Capability inventory: The agent is directed to generate code fixes, modify application logic (e.g., adding pagination, fixing N+1 queries), and update configuration headers based on its analysis.
- Sanitization: No input sanitization or validation steps are defined for the data processed during the measurement and identification phases.
Audit Metadata