gen-test-plan
Warn
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: MEDIUMINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the target repository's source code, directory structure, and commit messages to inform the test plan generation process. Malicious content within these files could attempt to subvert the agent's instructions.
- Ingestion points: Operations such as
git diff,git log, and multiplegrepcommands acrossSKILL.mdandreferences/stack-discovery.mdpull content directly from the repository environment. - Boundary markers: No delimiters or explicit instructions are provided to the agent to treat repository content as untrusted data or to ignore embedded instructions.
- Capability inventory: The agent can execute shell commands (
git,grep,python3), write to the local file system (test-plan.yaml), and potentially trigger network requests viacurlas defined in the test templates. - Sanitization: The skill lacks mechanisms to sanitize or filter the content retrieved from the repository before processing.
- [COMMAND_EXECUTION]: Several shell command templates in
SKILL.mdandreferences/stack-discovery.mdinterpolate variables (such as branch names from the--baseargument or module names discovered via grep) directly into shell strings without explicit sanitization. For example,git merge-base HEAD "origin/${BASE_BRANCH}"is vulnerable to command injection if the agent performs literal string substitution of a maliciously crafted branch name. - [DYNAMIC_EXECUTION]: The skill uses
python3 -cto execute a validation script at runtime during the 'Hard gates' verification phase. While the specific script for YAML parsing is benign, the pattern of dynamic execution on generated content is noted.
Audit Metadata