test-driven-development
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute test commands like
npm testto verify software behavior during the Red and Green phases of development. This is a standard and expected action for a coding-focused skill.- [PROMPT_INJECTION]: The skill contains strong procedural instructions, such as 'The Iron Law' and mandates to delete code if written before tests. These are interpreted as constraints for a specific development methodology rather than attempts to override agent safety or system instructions.- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the agent's interaction with user requirements and code generation. While this involves processing potentially untrusted data that could influence agent logic, the activity is confined to standard software engineering workflows. - Ingestion points: User-provided feature requirements and test files in SKILL.md and testing-anti-patterns.md.
- Boundary markers: Markdown code blocks are used for code and command delimiters.
- Capability inventory: Local execution of
npmfor testing. - Sanitization: No explicit validation of external input strings is defined in the instructions.
Audit Metadata