skills/grupous/gpus/testing-patterns/Gen Agent Trust Hub

testing-patterns

Pass

Audited by Gen Agent Trust Hub on Apr 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/test_runner.py executes system commands to perform test discovery and execution.
  • Evidence: Uses subprocess.run() to call npm, npx, or python with test-related modules.
  • Context: Commands are determined by project configuration files (package.json, pyproject.toml). While they execute code within the project, the script uses structured argument lists to prevent direct shell injection.
  • [PROMPT_INJECTION]: The skill has an indirect prompt injection surface due to processing external project data.
  • Ingestion points: Reads package.json and captures the output (stdout, stderr) of executed tests in scripts/test_runner.py.
  • Boundary markers: Absent; test output is printed directly to the agent's context without clear delimitation.
  • Capability inventory: The skill can execute shell commands via subprocess.run in scripts/test_runner.py.
  • Sanitization: Absent; the script does not filter or sanitize test output or package metadata before passing it to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 24, 2026, 09:21 AM
Security Audit — agent-trust-hub — testing-patterns