test-automation-expert

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFE
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The reference file references/ci-integration.md includes an integration example for the well-known service Codecov, which involves fetching and executing a script from https://codecov.io/bash. This is a standard and recognized integration pattern for this service.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a potential attack surface by reading and processing project files. 1. Ingestion points: Project source code and test files read via Read, Grep, and Glob tools. 2. Boundary markers: None explicitly defined in the skill instructions. 3. Capability inventory: Execution through a restricted Bash tool and file modifications via Write and Edit tools. 4. Sanitization: None implemented within the skill; command execution is governed by platform-level allowed-tools restrictions that limit execution to specific test-related command prefixes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 10:00 AM
Security Audit — agent-trust-hub — test-automation-expert