testing-preferred-patterns
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides various shell commands for developer auditing and test execution.
- Evidence:
references/fix-strategies.mdincludes Go, Python, and Node.js test runner commands (e.g.,go test -count=100,pytest --count=20,npx jest --repeat=20) and a bash script usinggrepto identify tests lacking assertions. - [EXTERNAL_DOWNLOADS]: The reference materials suggest the use of established third-party testing utilities.
- Evidence:
references/fix-strategies.mdprovides instructions to installpytest-repeatandpytest-randomlyviapip. These are well-known community plugins for the pytest framework. - [INDIRECT_PROMPT_INJECTION]: The skill processes external repository content, which presents a surface for indirect prompt injection.
- Ingestion points: The skill is designed to read
AGENTS.md, production source code, and existing test files within the target repository (SKILL.md). - Boundary markers: Instructions explicitly require a pre-defined 'brief' that identifies owned files and concrete findings before the agent begins edits.
- Capability inventory: The skill utilizes test runners and file system search tools (
grep) across multiple languages. - Sanitization: Behavior is constrained by the requirement to preserve observable behavior and follow specific patterns documented in the provided catalogs.
Audit Metadata