test-master
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of external codebases to design, write, and execute test suites. This creates an attack surface where malicious instructions embedded in the code-under-test (such as in comments or string literals) could potentially influence the agent's behavior during the test generation or execution phases.\n
- Ingestion points: User-provided codebase and feature requirements processed during the core workflow (SKILL.md).\n
- Boundary markers: Absent; no explicit delimiters or instructions are provided to the agent to treat input code as untrusted or to ignore embedded instructions during analysis.\n
- Capability inventory: The skill utilizes shell execution for multiple test runners including Jest, pytest, k6, and Playwright (references/automation-frameworks.md, references/performance-testing.md).\n
- Sanitization: Absent; there are no requirements for validating, filtering, or escaping content from the analyzed codebase before it is interpolated into test files or execution commands.
Audit Metadata