qa-test-planner

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze user-provided requirements and feature descriptions to generate test plans, which creates a surface for indirect prompt injection. 1. Ingestion points: Feature descriptions or requirement text processed during the Analyze Phase defined in SKILL.md. 2. Boundary markers: The instructions do not define delimiters or specific warnings to ignore embedded instructions within ingested data. 3. Capability inventory: The skill execution environment permits shell script execution and file system writes. 4. Sanitization: No explicit sanitization of ingested requirement text is performed before it is interpolated into prompts.
  • [DYNAMIC_EXECUTION]: The helper scripts provided with the skill contain a bash function that uses the eval command for variable assignment, presenting a command injection risk. 1. Evidence: In scripts/create_bug_report.sh and scripts/generate_test_cases.sh, the prompt_input function uses eval "$var_name="$input"". 2. Risk: Shell metacharacters in the input string could lead to arbitrary command execution within the agent's shell session.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 11:04 PM
Security Audit — agent-trust-hub — qa-test-planner