glean-verification
Pass
Audited by Gen Agent Trust Hub on Mar 24, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [SAFE]: The skill uses the 'glean' command-line utility for legitimate document management workflows, including listing pending verifications and marking documents as verified.- [COMMAND_EXECUTION]: Utilizes the 'glean' CLI for subcommands like 'list', 'verify', and 'remind'. This is consistent with the skill's stated purpose and reflects standard vendor functionality.- [PROMPT_INJECTION]: There is a potential surface for indirect prompt injection because the skill ingests document titles and metadata from the Glean platform. Ingestion points: 'glean verification list' (SKILL.md). Boundary markers: Absent. Capability inventory: 'glean verification verify' and 'glean verification remind' (SKILL.md). Sanitization: Absent. The risk is considered minimal in the context of verification workflows.
Audit Metadata