skills/duthaho/claudekit/test-first/Gen Agent Trust Hub

test-first

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The analyzed skill is entirely documentation-based, providing a step-by-step methodology for engineers to follow during development. It does not contain any shell scripts, configuration files, or executable code.
  • [PROMPT_INJECTION]: No patterns of system prompt override, safety bypass, or role-play injection were detected in the instructions.
  • [DATA_EXFILTRATION]: The skill does not access sensitive local file paths (such as .ssh or .aws) and does not contain any network-facing commands like curl or wget.
  • [REMOTE_CODE_EXECUTION]: No external packages, remote scripts, or dynamic execution patterns were identified. The references provided (Kent Beck, O'Reilly) are to well-known and trusted educational resources.
  • [INDIRECT_PROMPT_INJECTION]: While the skill involves processing external "Acceptance Criteria," it does so as an instructional framework for the agent's logical workflow rather than through programmatic data ingestion, presenting no identified surface for injection-based tool abuse.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 03:32 PM
Security Audit — agent-trust-hub — test-first