tdd-guide
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from user requirements and test coverage reports, which represents a potential attack surface for indirect prompt injection. While this is expected for the skill's primary function, it requires the agent to handle external data that could theoretically contain hidden instructions.\n
- Ingestion points: Untrusted data enters the skill via
scripts/coverage_analyzer.py(LCOV, JSON, and XML report parsing) andscripts/test_generator.py(requirements and user story dictionaries).\n - Boundary markers: The skill does not currently define explicit delimiters or instructions for the agent to ignore commands embedded within the processed data.\n
- Capability inventory: The skill is limited to static code analysis, quality metric calculation, and the generation of test stubs. It does not invoke privileged system operations, shell commands, or network requests using the ingested data.\n
- Sanitization: The modules use standard Python libraries for parsing. The
xml.etree.ElementTreeparser used inscripts/coverage_analyzer.pyis not inherently hardened against maliciously crafted XML entities (e.g., XXE), which is a common security consideration when processing external files.
Audit Metadata