tdd-workflow
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes feature requirements from user inputs as described in SKILL.md, which serves as an ingestion point for untrusted data. It lacks explicit boundary markers or sanitization logic. The skill possesses capabilities to create files and run shell commands such as npm test (documented in SKILL.md), creating a surface for indirect prompt injection findings.
- [COMMAND_EXECUTION]: The skill workflow involves executing shell commands, specifically npm test, to run test suites and verify code coverage as seen in SKILL.md.
Audit Metadata