test-helpers
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_CONTEXT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests various external project files to inform its code generation process, creating a potential vulnerability to malicious instructions embedded in those files.
- Ingestion points: Reads project configuration (
project.yaml), technical preferences, existing test files (tests/**/*_test.*), and design documents (design/gdd/*.md,tr-registry.yaml). - Boundary markers: The instructions do not specify any delimiters or safety markers to isolate the content of these files from the agent's core instructions.
- Capability inventory: The skill utilizes
Read,Glob,Grep, andWritetools to interact with the file system. - Sanitization: No sanitization or validation logic is defined for the content extracted from these files before it is processed.
- [DYNAMIC_CONTEXT_INJECTION]: The skill employs dynamic context injection to execute shell commands at load time for environment configuration.
- Evidence: The file contains the command
!"source "${CLAUDE_PROJECT_DIR:-.}/.claude/hooks/yaml-helper.sh" 2>/dev/null && resolve_config --keys automation"which runs a project-specific script to resolve automation settings when the skill is accessed.
Audit Metadata