tdd
Pass
Audited by Gen Agent Trust Hub on Aug 3, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill requires the agent to ingest and analyze external data sources including project code and test suites, which serves as a potential vector for indirect prompt injection attacks.
- Ingestion points: The agent is instructed to inspect existing tests, public interfaces, and project conventions within the user's codebase (SKILL.md).
- Boundary markers: The instructions lack specific delimiters or warnings to ignore directives that might be embedded within the project files being analyzed.
- Capability inventory: The agent is empowered to write production code and execute test commands based on the context it extracts from these files.
- Sanitization: There are no instructions for sanitizing, escaping, or validating the content extracted from external project files.
Audit Metadata