test-lab

Fail

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [CREDENTIALS_UNSAFE]: Hardcoded database credentials detected in verification scripts.
  • Evidence found in tests/ingest-sparta/verify_ingest_sparta.sh: ARANGO_PASS="${ARANGO_PASS:-openSesame}" and curl -sf -u root:openSesame.
  • Evidence found in tests/memory-database/verify_memory_database.sh: ARANGO_PASS="${ARANGO_PASS:-openSesame}" and curl -sf -u root:openSesame.
  • [COMMAND_EXECUTION]: The skill facilitates arbitrary code execution as part of its core testing functionality.
  • Python Execution: In service.py, the _run_python_assertion function executes arbitrary code strings using subprocess.run(["python3", "-c", test_code], ...).
  • Shell Execution: In service.py, the _run_shell_assertion function executes arbitrary shell commands using subprocess.run(["bash", "-c", assertion], ...).
  • External Script Invocation: generators/behavioral_tests.py uses subprocess.run to execute run.sh entry points found in arbitrary target directories.
  • Tool Chaining: generators/python_tests.py and generators/service_tests.py execute the run.sh script from the treesitter skill to perform AST-based analysis.
  • [EXTERNAL_DOWNLOADS]: Verification scripts perform network requests to local infrastructure endpoints.
  • Files tests/ingest-sparta/verify_ingest_sparta.sh and tests/memory-database/verify_memory_database.sh use curl to query a local ArangoDB instance at http://127.0.0.1:8529.
Recommendations
  • HIGH: Downloads and executes remote code from: http://127.0.0.1:8529/_db/memory/_api/index?collection=lessons, http://127.0.0.1:8529/_db/memory/_api/index?collection=sparta_qra - DO NOT USE without thorough review
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jun 18, 2026, 05:05 AM
Security Audit — agent-trust-hub — test-lab