managing-jest
Pass
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The helper function
jest_runinSKILL.mdinterpolates the$argsvariable into a shell command (npx jest $args ...) without shell-quoting or sanitization. This allows for arbitrary command injection if the agent passes unsanitized user input into the function arguments.\n- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection due to its processing of untrusted repository files.\n - Ingestion points: The skill reads
package.json,jest.config.js,jest.config.ts,jest-results.json, andcoverage/coverage-summary.json(documented inSKILL.md).\n - Boundary markers: Absent; there are no delimiters or instructions to ignore embedded instructions within the processed files.\n
- Capability inventory: The skill can execute shell commands via
npx jestand evaluate code vianode -e(documented inSKILL.md).\n - Sanitization: Absent; the skill directly parses file contents using tools like
grep,cat, andjqwithout validation or escaping.
Audit Metadata