wd-test-format

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • File Embedding for Test Fixtures: The skill demonstrates how to use the embed directive to include external file contents, such as certificates or test data, into the worker's environment. This is a standard mechanism for providing test workers with necessary static assets.
  • Network Access Configuration: Documentation is provided for configuring outbound network permissions within tests (e.g., allow = ["private"]). This capability is intended for verifying that workers can correctly interact with defined network services.
  • Task Runner Integration: The guide includes examples of CLI commands using the just task runner to automate test scaffolding and execution, which is typical for the project's development environment.
  • Service and Environment Bindings: The skill outlines how to define various environment bindings, including Durable Object namespaces and service bindings, which are fundamental to the Worker programming model.
  • Indirect Prompt Injection Surface Analysis:
  • Ingestion points: The .wd-test format utilizes the embed keyword to read content from the local filesystem (documented in SKILL.md and reference/advanced-configs.md).
  • Boundary markers: The use of the Cap'n Proto configuration schema provides a structured way to define these embeddings.
  • Capability inventory: The skill details capabilities for disk access via disk services and network access via network configurations.
  • Sanitization: The documentation focuses on configuration syntax; the workerd runtime is designed to enforce the security boundaries defined in these files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 04:04 PM
Security Audit — agent-trust-hub — wd-test-format