python-testing
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines patterns for an agent to generate and execute Python test suites. This creates a surface for indirect prompt injection if the agent applies these instructions to untrusted code or requirements provided by an external source.
- Ingestion points: The skill is activated when writing or reviewing Python code, which involves processing project files and developer requirements.
- Boundary markers: No explicit instructions are provided to the agent to isolate or treat external code as untrusted during the testing process.
- Capability inventory: The patterns include file system operations (tmp_path, os.remove), network request mocking, and shell command execution for running tests (pytest).
- Sanitization: The skill does not include specific guidance for sanitizing or sandboxing the environment when executing tests on third-party code.
Audit Metadata