test-suite-cleanup

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and act upon untrusted data from the repository being cleaned, including contribution docs, manifests, CI workflows, and test files. This creates a potential surface where malicious instructions embedded in the repository could attempt to influence the agent's behavior during the audit or remediation phases.
  • Ingestion points: The skill reads repository instructions, manifests, CI workflows, and test configuration in Step 1 and Step 2.
  • Boundary markers: The skill employs a multi-agent architectural separation (Orchestrator, Explorer, Oracle, Fixer), but does not explicitly define prompt-level delimiters or 'ignore' instructions for the untrusted data it processes.
  • Capability inventory: The skill has the capability to execute shell-based test commands and modify test files.
  • Sanitization: No explicit sanitization or validation logic is defined for the content extracted from repository files before it is used to determine execution logic.
  • [COMMAND_EXECUTION]: The skill is authorized to discover and execute 'test commands' found within the repository. While this is the intended primary purpose (cleaning and verifying test suites), it involves running potentially arbitrary shell commands (e.g., test runners, stress modes) that are defined in the project's own configuration files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 01:25 AM
Security Audit — agent-trust-hub — test-suite-cleanup