test-flakiness
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_CONTEXT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external sources including CI logs and test result files (e.g., .xml, .log). An attacker who can influence test names, error messages, or failure logs could attempt to inject malicious instructions into the agent's context during the parsing and reporting phases.
- Ingestion points: Test result artifacts in .github/, test-results/, and Saved/Logs/.
- Boundary markers: The skill does not define explicit delimiters or instructions to ignore embedded commands within log data.
- Capability inventory: The skill has the ability to write files (regression-suite.md) and execute bash commands, which could be abused if an injection is successful.
- Sanitization: No sanitization or validation of log content is specified before the data is processed or reported.
- [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes the
!commandsyntax to execute a shell script (yaml-helper.sh) at load time for configuration resolution. While this appears to be for legitimate automation settings, it represents a mechanism for code execution that occurs automatically when the skill is accessed.
Audit Metadata