fincept-qa

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute standard development and build tools such as cargo test, cargo clippy, bun run build, and python -m pytest as part of its quality gate definitions. These are routine operations within a software development and QA context.
  • [COMMAND_EXECUTION]: In its testing patterns, the skill utilizes subprocess.run to execute local Python scripts and verify their JSON outputs, which is a standard method for automated script testing.
  • [PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection because it ingests data from external sources like test logs, script outputs, and local database records. Ingestion points: Test logs, standard output from test scripts, and SQLite database entries (SKILL.md). Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands in the processed logs. Capability inventory: The skill has the capability to execute system commands and Python scripts (SKILL.md). Sanitization: There is no mention of input sanitization or validation for the data being processed.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 06:19 PM
Security Audit — agent-trust-hub — fincept-qa