test-lab
Fail
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [CREDENTIALS_UNSAFE]: Hardcoded database credentials detected in verification scripts.
- Evidence found in
tests/ingest-sparta/verify_ingest_sparta.sh:ARANGO_PASS="${ARANGO_PASS:-openSesame}"andcurl -sf -u root:openSesame. - Evidence found in
tests/memory-database/verify_memory_database.sh:ARANGO_PASS="${ARANGO_PASS:-openSesame}"andcurl -sf -u root:openSesame. - [COMMAND_EXECUTION]: The skill facilitates arbitrary code execution as part of its core testing functionality.
- Python Execution: In
service.py, the_run_python_assertionfunction executes arbitrary code strings usingsubprocess.run(["python3", "-c", test_code], ...). - Shell Execution: In
service.py, the_run_shell_assertionfunction executes arbitrary shell commands usingsubprocess.run(["bash", "-c", assertion], ...). - External Script Invocation:
generators/behavioral_tests.pyusessubprocess.runto executerun.shentry points found in arbitrary target directories. - Tool Chaining:
generators/python_tests.pyandgenerators/service_tests.pyexecute therun.shscript from thetreesitterskill to perform AST-based analysis. - [EXTERNAL_DOWNLOADS]: Verification scripts perform network requests to local infrastructure endpoints.
- Files
tests/ingest-sparta/verify_ingest_sparta.shandtests/memory-database/verify_memory_database.shusecurlto query a local ArangoDB instance athttp://127.0.0.1:8529.
Recommendations
- HIGH: Downloads and executes remote code from: http://127.0.0.1:8529/_db/memory/_api/index?collection=lessons, http://127.0.0.1:8529/_db/memory/_api/index?collection=sparta_qra - DO NOT USE without thorough review
- AI detected serious security threats
Audit Metadata