test-anti-patterns

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external data, which inherently introduces a vulnerability surface.
  • Ingestion points: The Inputs section in SKILL.md explicitly lists 'Test code' and 'Production code' as data provided by the user for processing.
  • Boundary markers: The skill workflow does not instruct the agent to use delimiters or 'ignore embedded instructions' warnings when reading and analyzing the content of these external files.
  • Capability inventory: The skill is restricted to file-reading and analysis; it does not request high-risk capabilities such as network access, file-writing, or shell command execution in its instructions.
  • Sanitization: There are no instructions provided for sanitizing or validating the content of the ingested code files before they are processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 01:25 AM
Security Audit — agent-trust-hub — test-anti-patterns