aspire-integration-testing
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for installing and using the Aspire CLI tool (
dotnet tool install -g aspire.cli) and running commands such asaspire mcp initandaspire run. These are standard developer operations for the .NET Aspire ecosystem. - [EXTERNAL_DOWNLOADS]: The skill references several official NuGet packages (e.g.,
Aspire.Hosting.Testing,xunit) and the installation of theaspire.clitool from the .NET tool registry. - [INDIRECT_PROMPT_INJECTION]: The skill describes how to enable MCP (Model Context Protocol) integration, which allows AI agents to query the state of a running application, including console logs and distributed traces. This creates a surface where data generated by the application (which may include untrusted input) is ingested into the agent's context.
- Ingestion points: Resource states, console logs, and distributed traces accessed via the MCP server (
ci-and-tooling.md). - Boundary markers: None specified; the agent is instructed to query the state directly.
- Capability inventory: The agent can view real-time logs and investigate telemetry spans across the distributed system.
- Sanitization: No specific instructions are provided for sanitizing or delimiting the data ingested from logs and traces.
Audit Metadata