aspire-integration-testing

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for installing and using the Aspire CLI tool (dotnet tool install -g aspire.cli) and running commands such as aspire mcp init and aspire run. These are standard developer operations for the .NET Aspire ecosystem.
  • [EXTERNAL_DOWNLOADS]: The skill references several official NuGet packages (e.g., Aspire.Hosting.Testing, xunit) and the installation of the aspire.cli tool from the .NET tool registry.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes how to enable MCP (Model Context Protocol) integration, which allows AI agents to query the state of a running application, including console logs and distributed traces. This creates a surface where data generated by the application (which may include untrusted input) is ingested into the agent's context.
  • Ingestion points: Resource states, console logs, and distributed traces accessed via the MCP server (ci-and-tooling.md).
  • Boundary markers: None specified; the agent is instructed to query the state directly.
  • Capability inventory: The agent can view real-time logs and investigate telemetry spans across the distributed system.
  • Sanitization: No specific instructions are provided for sanitizing or delimiting the data ingested from logs and traces.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 07:15 PM
Security Audit — agent-trust-hub — aspire-integration-testing