gen-test-plan

Warn

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: MEDIUMINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the target repository's source code, directory structure, and commit messages to inform the test plan generation process. Malicious content within these files could attempt to subvert the agent's instructions.
  • Ingestion points: Operations such as git diff, git log, and multiple grep commands across SKILL.md and references/stack-discovery.md pull content directly from the repository environment.
  • Boundary markers: No delimiters or explicit instructions are provided to the agent to treat repository content as untrusted data or to ignore embedded instructions.
  • Capability inventory: The agent can execute shell commands (git, grep, python3), write to the local file system (test-plan.yaml), and potentially trigger network requests via curl as defined in the test templates.
  • Sanitization: The skill lacks mechanisms to sanitize or filter the content retrieved from the repository before processing.
  • [COMMAND_EXECUTION]: Several shell command templates in SKILL.md and references/stack-discovery.md interpolate variables (such as branch names from the --base argument or module names discovered via grep) directly into shell strings without explicit sanitization. For example, git merge-base HEAD "origin/${BASE_BRANCH}" is vulnerable to command injection if the agent performs literal string substitution of a maliciously crafted branch name.
  • [DYNAMIC_EXECUTION]: The skill uses python3 -c to execute a validation script at runtime during the 'Hard gates' verification phase. While the specific script for YAML parsing is benign, the pattern of dynamic execution on generated content is noted.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 20, 2026, 09:17 AM
Security Audit — agent-trust-hub — gen-test-plan