testing-preferred-patterns

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides various shell commands for developer auditing and test execution.
  • Evidence: references/fix-strategies.md includes Go, Python, and Node.js test runner commands (e.g., go test -count=100, pytest --count=20, npx jest --repeat=20) and a bash script using grep to identify tests lacking assertions.
  • [EXTERNAL_DOWNLOADS]: The reference materials suggest the use of established third-party testing utilities.
  • Evidence: references/fix-strategies.md provides instructions to install pytest-repeat and pytest-randomly via pip. These are well-known community plugins for the pytest framework.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external repository content, which presents a surface for indirect prompt injection.
  • Ingestion points: The skill is designed to read AGENTS.md, production source code, and existing test files within the target repository (SKILL.md).
  • Boundary markers: Instructions explicitly require a pre-defined 'brief' that identifies owned files and concrete findings before the agent begins edits.
  • Capability inventory: The skill utilizes test runners and file system search tools (grep) across multiple languages.
  • Sanitization: Behavior is constrained by the requirement to preserve observable behavior and follow specific patterns documented in the provided catalogs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 01:25 AM
Security Audit — agent-trust-hub — testing-preferred-patterns