test
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted repository content, specifications, and examples to generate test suites, which is an inherent surface for indirect prompt injection.
- Ingestion points: The skill ingests source code, specification files, and "beads" or examples from the conversation history to derive test logic.
- Boundary markers: Not explicitly defined in the instructions for separating ingested code from agent instructions.
- Capability inventory: The skill is authorized to write files (
write_test_files), modify source code (modify_source_files), and execute shell commands (repository-native test runners). - Sanitization: While no automated sanitization is described, the skill provides a mandatory "Safety Gate" in
references/real-service-e2e.mdthat instructs the agent to verify non-production environments and use isolated credentials, significantly reducing the impact of potential injection-driven actions. - [COMMAND_EXECUTION]: The skill includes a local validation script (
scripts/validate.sh) used for verifying the structural integrity of theSKILL.mdfile. The script uses standard utilities (grep, head, cut) and operates exclusively on local files with no network interaction or argument injection risks.
Audit Metadata