tdd-red-green-refactor
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines a process for the agent to read, write, and execute external code and test files (e.g., using Vitest or Jest). This creates a surface where instructions hidden within the code or test data could attempt to influence the agent's behavior.\n
- Ingestion points: The agent processes user-provided or generated TypeScript source files and test specifications (e.g., math.test.ts, math.ts) as part of the Red-Green-Refactor loop.\n
- Boundary markers: Absent. The skill provides no instructions for using delimiters or specific 'ignore' directives to separate code logic from instructions when reading files.\n
- Capability inventory: The workflow requires the agent to have file system write access and the ability to execute shell commands to run test suites.\n
- Sanitization: Absent. There is no requirement or mechanism specified for the agent to sanitize or validate the content of the files it processes before execution.
Audit Metadata