test-falsify

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection during its test analysis phases.
  • Ingestion points: The skill reads local test files to extract bug declarations, intent, and user requirements in Phase 1 and Phase 4.
  • Boundary markers: The instructions lack explicit delimiters or warnings to ignore embedded directives within the files being processed.
  • Capability inventory: The skill is configured with access to Read, Bash, Grep, and Glob tools.
  • Sanitization: There is no validation or sanitization of content extracted from code comments or docstrings before it enters the agent context.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 05:07 PM
Security Audit — agent-trust-hub — test-falsify