test-evidence-review

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_CONTEXT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes data from story files, sprint plans, and test source code to evaluate quality. Maliciously crafted instructions within these files could attempt to manipulate the agent's review logic or output.
  • Ingestion points: Processes files found in production/epics/, production/sprints/, and various source code test directories (e.g., tests/unit/).
  • Boundary markers: Absent. The skill uses Grep with context flags (e.g., -A 8) to extract text blocks directly into the session context without delimiters.
  • Capability inventory: Access to Bash, Write, Read, Glob, and Grep tools.
  • Sanitization: No evidence of sanitization, escaping, or instruction-ignoring warnings applied to external content before interpolation.
  • [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes the ! command syntax in SKILL.md to execute bash "${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh" resolve_config ... during the skill loading phase. This allows shell execution to occur automatically without explicit user confirmation for that specific step.
  • [COMMAND_EXECUTION]: The skill performs several command-line operations, including using Grep to extract story data and Bash to execute a local configuration hook. These tools are used to traverse the file system and interact with local project scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 06:51 PM
Security Audit — agent-trust-hub — test-evidence-review