assertion-quality

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • Indirect Prompt Injection Surface: The skill is designed to ingest and analyze external test and production code files. This creates a potential surface where malicious instructions embedded within the analyzed code (such as in comments or strings) could influence the agent's behavior.\n
  • Ingestion points: The workflow involves reading all test files and project directories provided by the user to identify assertion patterns (Workflow Step 2).\n
  • Capability inventory: The skill utilizes tool-calling capabilities to access language extensions and performs file-reading operations across the codebase to generate metrics reports.\n
  • Boundary markers: The instructions do not specify the use of delimiters or 'ignore' directives to distinguish the code being analyzed from the agent's instructions.\n
  • Sanitization: The workflow does not currently include a step for sanitizing or escaping the content of the files before processing them for metrics.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:06 PM
Security Audit — agent-trust-hub — assertion-quality