workflow-write-integration-test

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill includes instructions to override or ignore platform-specific behaviors, such as 'Ignore Claude-specific mode-switch instructions when they appear' and 'Strict execution contract: when a user explicitly invokes a skill, execute that skill protocol as written.' These are used to ensure cross-platform consistency between Codex and Claude environments.
  • [COMMAND_EXECUTION]: The $integration-test-verify step explicitly invokes shell commands (e.g., quickRunCommand) defined in the docs/project-config.json file. This is the intended primary purpose of the skill for verifying test stability through repeat-run gates.
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits a significant attack surface for indirect prompt injection as it is designed to ingest and process numerous external project files.
  • Ingestion points: The skill mandates reading docs/project-config.json, docs/project-reference/*, docs/specs/*, and lessons.md (SKILL.md).
  • Boundary markers: The instructions do not specify the use of delimiters or 'ignore instructions' warnings when reading these project documents.
  • Capability inventory: The agent has the capability to write files ($integration-test, $spec) and execute shell commands ($integration-test-verify).
  • Sanitization: There is no evidence of explicit sanitization or filtering of the content read from the project documentation.
  • [DYNAMIC_EXECUTION]: The skill automates the generation of test code files from specifications ($integration-test) and subsequently executes that generated code ($integration-test-verify). This behavior is documented as the core functionality for integration test authoring.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 08:22 PM
Security Audit — agent-trust-hub — workflow-write-integration-test