tdd-red-green-refactor

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a process for the agent to read, write, and execute external code and test files (e.g., using Vitest or Jest). This creates a surface where instructions hidden within the code or test data could attempt to influence the agent's behavior.\n
  • Ingestion points: The agent processes user-provided or generated TypeScript source files and test specifications (e.g., math.test.ts, math.ts) as part of the Red-Green-Refactor loop.\n
  • Boundary markers: Absent. The skill provides no instructions for using delimiters or specific 'ignore' directives to separate code logic from instructions when reading files.\n
  • Capability inventory: The workflow requires the agent to have file system write access and the ability to execute shell commands to run test suites.\n
  • Sanitization: Absent. There is no requirement or mechanism specified for the agent to sanitize or validate the content of the files it processes before execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 04:14 AM