test-automation-expert
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFE
Full Analysis
- [REMOTE_CODE_EXECUTION]: The reference file
references/ci-integration.mdincludes an integration example for the well-known service Codecov, which involves fetching and executing a script fromhttps://codecov.io/bash. This is a standard and recognized integration pattern for this service. - [INDIRECT_PROMPT_INJECTION]: The skill possesses a potential attack surface by reading and processing project files. 1. Ingestion points: Project source code and test files read via
Read,Grep, andGlobtools. 2. Boundary markers: None explicitly defined in the skill instructions. 3. Capability inventory: Execution through a restrictedBashtool and file modifications viaWriteandEdittools. 4. Sanitization: None implemented within the skill; command execution is governed by platform-levelallowed-toolsrestrictions that limit execution to specific test-related command prefixes.
Audit Metadata