test-evidence-review
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_CONTEXT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes data from story files, sprint plans, and test source code to evaluate quality. Maliciously crafted instructions within these files could attempt to manipulate the agent's review logic or output.
- Ingestion points: Processes files found in
production/epics/,production/sprints/, and various source code test directories (e.g.,tests/unit/). - Boundary markers: Absent. The skill uses Grep with context flags (e.g.,
-A 8) to extract text blocks directly into the session context without delimiters. - Capability inventory: Access to
Bash,Write,Read,Glob, andGreptools. - Sanitization: No evidence of sanitization, escaping, or instruction-ignoring warnings applied to external content before interpolation.
- [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes the
!command syntax inSKILL.mdto executebash "${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh" resolve_config ...during the skill loading phase. This allows shell execution to occur automatically without explicit user confirmation for that specific step. - [COMMAND_EXECUTION]: The skill performs several command-line operations, including using
Grepto extract story data andBashto execute a local configuration hook. These tools are used to traverse the file system and interact with local project scripts.
Audit Metadata