test-it

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external repository sources such as issue descriptions, pull request metadata, and BDD scenarios to determine test requirements.\n
  • Ingestion points: Repository files, issues, and PR descriptions.\n
  • Boundary markers: Not explicitly specified in the instructions for prompt interpolation.\n
  • Capability inventory: Includes file writing and execution of repository-defined test commands.\n
  • Sanitization: The instructions mandate redacting secrets from fixtures and snapshots.\n- [COMMAND_EXECUTION]: The skill instructs the agent to discover and run local test suites using standard tools like pytest, cargo test, or package.json scripts.\n- [NO_CODE]: The skill consists entirely of markdown instructions and YAML configuration metadata, without bundled scripts or binaries.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 11:26 PM
Security Audit — agent-trust-hub — test-it