stelow-workflow-testing-execution

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute local unit test runners, specifically 'go test', 'npm test', and 'pytest', to verify code logic during Phase 3 of the protocol.
  • [INDIRECT_PROMPT_INJECTION]: The skill performs QA and UX audits by ingesting untrusted data, which could contain malicious instructions designed to influence the agent's behavior or reporting.
  • Ingestion points: Source code files analyzed in Codebase mode, live website URLs processed for browser audits, and UI screenshots.
  • Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded prompts within the analyzed code or site content.
  • Capability inventory: The skill has the ability to execute shell commands (test runners), interact with a browser (agent-browser), and write audit findings to the local filesystem (.stelow-ux-critique/).
  • Sanitization: There is no evidence of sanitization, filtering, or escaping of the content ingested from external sources or code files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 09:05 PM
Security Audit — agent-trust-hub — stelow-workflow-testing-execution