integration-test-verify

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill executes shell commands specified in the project's docs/project-config.json file, specifically the systemCheckCommand to verify environment readiness and the quickRunCommand to run the test suites. These executions are necessary for the skill's primary function as a test runner.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The instructions direct the agent to 'harvest' environment preconditions from project documentation and scripts. This explicitly involves identifying and documenting sensitive details such as credentials, environment variables, and ports needed for the testing environment, which are then used to gate the test execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and act upon instructions found in project-specific reference documents and configuration files. This creates a surface for indirect prompt injection, as the agent derives its specific execution checklists and verification steps from these external, repository-resident sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 08:23 PM
Security Audit — agent-trust-hub — integration-test-verify