tdd-workflow

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external *.plan.md files, which serves as a vector for indirect prompt injection. However, the skill provides explicit, high-quality defensive instructions to mitigate this risk.
  • Ingestion points: The skill reads implementation plans from user-provided file paths (*.plan.md) as defined in the Plan Handoff section of SKILL.md.
  • Boundary markers: It explicitly instructs the agent to treat plan content as data rather than instructions and provides a 'Plan safety checklist' to identify and ignore override attempts.
  • Capability inventory: The skill utilizes shell-based testing tools (npm test, npm run test:coverage), browser automation (Playwright), and version control systems (git).
  • Sanitization: It mandates human review for all shell commands and network installers, rejects destructive filesystem operations, and restricts validation steps to a pre-defined whitelist of project-appropriate actions.
  • [COMMAND_EXECUTION]: The skill requires the execution of local shell commands for testing, coverage reporting, and Git checkpointing. While these are standard development tasks, they involve subprocess calls guided by the TDD workflow logic.
  • [PROMPT_INJECTION]: Static analysis flagged potential injection patterns related to overriding instructions. Upon manual review, these occurrences in SKILL.md are defensive instructions (e.g., 'disregard governing instructions') designed to teach the agent to detect and ignore injections within the provided plan files, rather than being malicious injections themselves.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:40 PM
Security Audit — agent-trust-hub — tdd-workflow