run-test-plan

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes arbitrary shell commands retrieved from a YAML test plan file, including setup scripts, build commands, background services, and individual test steps through Bash.
  • [DYNAMIC_EXECUTION]: Shell commands are dynamically constructed and executed using Bash throughout the setup and test execution phases, based on strings provided in the external YAML input.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from a YAML test plan that controls execution logic and command parameters, creating a vulnerability surface for indirect injection.
  • Ingestion points: The YAML test plan loaded from the path specified by the --plan argument (defaulting to docs/testing/test-plan.yaml).
  • Boundary markers: No markers or instructions are used to delimit or ignore potentially malicious content within the YAML file.
  • Capability inventory: Full shell command execution, network requests via curl, file system writes to docs/testing/evidence/, and browser automation via the agent-browser CLI.
  • Sanitization: Although yaml.safe_load is used for parsing, no validation or sanitization is performed on the resulting command strings before execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 09:16 AM
Security Audit — agent-trust-hub — run-test-plan