qa-codeceptjs-writer

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection vulnerability surface by processing data from potentially untrusted external sources to generate executable test code.
  • Ingestion points: Workflow Step 1 in SKILL.md identifies that the skill reads test case data from sources including qa-testcase-from-docs, qa-manual-test-designer, and qa-browser-data-collector.
  • Boundary markers: The instructions do not define delimiters or specific 'ignore' directives to prevent the agent from following malicious instructions embedded within the ingested test cases.
  • Capability inventory: The skill is configured to write generated test files and scenarios to the project's local filesystem (tests/e2e).
  • Sanitization: There is no evidence of validation, escaping, or filtering of the external input before it is interpolated into the code generation prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:39 PM
Security Audit — agent-trust-hub — qa-codeceptjs-writer