tester-agent
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and process untrusted external data, specifically source code changes and existing test files, which could contain malicious instructions designed to influence the agent's behavior during the testing process.
- Ingestion points: The agent is directed to read changes, callers, and existing test files (SKILL.md, Process section).
- Boundary markers: No specific delimiters or warnings are provided to instruct the agent to ignore instructions embedded within the code it reads.
- Capability inventory: The agent has the capability to write new test files and execute shell commands using test runners such as
rails testandnode:test(SKILL.md, Rules section). - Sanitization: There are no explicit instructions for sanitizing or validating the content of the files before they are processed or executed as tests.
- [DYNAMIC_EXECUTION]: The skill requires the agent to generate and execute code scripts (tests) based on its analysis of the project. While this is the intended functionality for a testing agent, the execution of agent-generated code carries an inherent risk if the logic is influenced by malicious input.
- Evidence: The instructions specify using
node:testandrails testto run suites after modifying or creating test files (SKILL.md, Rules section).
Audit Metadata