testing-web

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes a local bash script scripts/verify.sh used to statically lint test files for anti-patterns (e.g., missing assertions, unawaited events). The script performs read-only file operations using standard utilities like grep and find and does not execute the files it scans.
  • [COMMAND_EXECUTION]: The instructions suggest using npx stryker run for mutation testing, which is a standard industry tool for improving test suite quality.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and modify frontend test files. While this presents an attack surface for indirect prompt injection if an attacker embeds malicious instructions in a project's test files, this risk is typical for code-related skills and is mitigated by the skill's focus on specific, structured testing patterns.
  • Ingestion points: The agent reads and analyzes existing *.test.ts, *.spec.ts, and similar source files.
  • Boundary markers: None explicitly defined within the skill content.
  • Capability inventory: The skill allows for reading and writing local source files and provides a script for linting them.
  • Sanitization: The skill does not provide explicit sanitization logic for ingested test content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 08:57 AM
Security Audit — agent-trust-hub — testing-web