skills/cniska/skills/test-review/Gen Agent Trust Hub

test-review

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external code diffs and test files. This creates an inherent attack surface for indirect prompt injection, where instructions embedded in the code being reviewed (such as in comments or strings) could potentially influence the agent's behavior. However, the skill does not contain any instructions that would facilitate this vulnerability beyond the standard risks associated with processing untrusted data.
  • [SAFE]: The instructions focus entirely on best practices for software testing and code quality. There are no attempts to access sensitive files, execute arbitrary commands, exfiltrate data, or obfuscate intent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 09:15 AM
Security Audit — agent-trust-hub — test-review