managing-jest

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The helper function jest_run in SKILL.md interpolates the $args variable into a shell command (npx jest $args ...) without shell-quoting or sanitization. This allows for arbitrary command injection if the agent passes unsanitized user input into the function arguments.\n- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection due to its processing of untrusted repository files.\n
  • Ingestion points: The skill reads package.json, jest.config.js, jest.config.ts, jest-results.json, and coverage/coverage-summary.json (documented in SKILL.md).\n
  • Boundary markers: Absent; there are no delimiters or instructions to ignore embedded instructions within the processed files.\n
  • Capability inventory: The skill can execute shell commands via npx jest and evaluate code via node -e (documented in SKILL.md).\n
  • Sanitization: Absent; the skill directly parses file contents using tools like grep, cat, and jq without validation or escaping.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 04:21 PM
Security Audit — agent-trust-hub — managing-jest