qa-mobile-test-writer

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's workflow involves ingesting data from external sources such as qa-testcase-from-docs, qa-manual-test-designer, and qa-testcase-from-ui. These inputs are used to autonomously generate test scripts written to the local file system (output_dir: tests/mobile).
  • Ingestion points: SKILL.md identifies structured test cases from multiple documentation and UI-based sources as primary inputs.
  • Boundary markers: No specific delimiters or instructions to ignore embedded commands within the ingested test cases were found in the provided files.
  • Capability inventory: The skill has autonomous file-writing capabilities to the project directory.
  • Sanitization: The provided documentation does not specify sanitization or validation routines for the content parsed from external test cases before interpolation into generated scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 02:34 PM
Security Audit — agent-trust-hub — qa-mobile-test-writer