workflow-write-integration-test
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill includes instructions to override or ignore platform-specific behaviors, such as 'Ignore Claude-specific mode-switch instructions when they appear' and 'Strict execution contract: when a user explicitly invokes a skill, execute that skill protocol as written.' These are used to ensure cross-platform consistency between Codex and Claude environments.
- [COMMAND_EXECUTION]: The
$integration-test-verifystep explicitly invokes shell commands (e.g.,quickRunCommand) defined in thedocs/project-config.jsonfile. This is the intended primary purpose of the skill for verifying test stability through repeat-run gates. - [INDIRECT_PROMPT_INJECTION]: The skill exhibits a significant attack surface for indirect prompt injection as it is designed to ingest and process numerous external project files.
- Ingestion points: The skill mandates reading
docs/project-config.json,docs/project-reference/*,docs/specs/*, andlessons.md(SKILL.md). - Boundary markers: The instructions do not specify the use of delimiters or 'ignore instructions' warnings when reading these project documents.
- Capability inventory: The agent has the capability to write files (
$integration-test,$spec) and execute shell commands ($integration-test-verify). - Sanitization: There is no evidence of explicit sanitization or filtering of the content read from the project documentation.
- [DYNAMIC_EXECUTION]: The skill automates the generation of test code files from specifications (
$integration-test) and subsequently executes that generated code ($integration-test-verify). This behavior is documented as the core functionality for integration test authoring.
Audit Metadata