testing-web
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes a local bash script
scripts/verify.shused to statically lint test files for anti-patterns (e.g., missing assertions, unawaited events). The script performs read-only file operations using standard utilities likegrepandfindand does not execute the files it scans. - [COMMAND_EXECUTION]: The instructions suggest using
npx stryker runfor mutation testing, which is a standard industry tool for improving test suite quality. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and modify frontend test files. While this presents an attack surface for indirect prompt injection if an attacker embeds malicious instructions in a project's test files, this risk is typical for code-related skills and is mitigated by the skill's focus on specific, structured testing patterns.
- Ingestion points: The agent reads and analyzes existing
*.test.ts,*.spec.ts, and similar source files. - Boundary markers: None explicitly defined within the skill content.
- Capability inventory: The skill allows for reading and writing local source files and provides a script for linting them.
- Sanitization: The skill does not provide explicit sanitization logic for ingested test content.
Audit Metadata