verification-before-completion

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [Indirect Prompt Injection] (LOW): The skill creates a surface for indirect prompt injection through its verification workflow.\n
  • Ingestion points: The agent processes untrusted data from VCS diffs and other agents' success reports as described in the 'Key Patterns' and 'When To Apply' sections of SKILL.md.\n
  • Boundary markers: There are no instructions to use delimiters or ignore embedded commands within the ingested data.\n
  • Capability inventory: The agent is tasked with running shell commands (tests, builds, linters) based on the verification needs.\n
  • Sanitization: The skill does not prescribe any sanitization or validation of the external content before processing.\n- [NO_CODE] (SAFE): No code or scripts were found in the skill; it consists solely of markdown instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:48 PM