skills/grahama1970/agent-skills/test/Gen Agent Trust Hub

test

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local scripts like sanity.sh and lint.sh, as well as standard test frameworks using Python's subprocess.run module. The implementation uses command lists rather than shell strings, effectively mitigating risks of shell injection vulnerabilities.
  • [EXTERNAL_DOWNLOADS]: The run.sh script uses the uv tool to manage the Python environment and install specified dependencies from official package registries. This is a standard and expected behavior for maintaining reproducible development environments.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface because it processes untrusted data from the local environment. Ingestion points: test_runner.py reads the contents of package.json files and captures the stdout/stderr from executed test suites. Boundary markers: The current implementation lacks explicit instructions or markers to prevent the AI from interpreting instructions found within test outputs. Capability inventory: The skill can execute various shell commands through the test runners it manages. Sanitization: The tool performs standard JSON parsing for metadata but does not filter captured terminal output for potentially malicious natural language instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:37 AM
Security Audit — agent-trust-hub — test