testing-patterns
Pass
Audited by Gen Agent Trust Hub on Apr 24, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/test_runner.pyexecutes system commands to perform test discovery and execution. - Evidence: Uses
subprocess.run()to callnpm,npx, orpythonwith test-related modules. - Context: Commands are determined by project configuration files (
package.json,pyproject.toml). While they execute code within the project, the script uses structured argument lists to prevent direct shell injection. - [PROMPT_INJECTION]: The skill has an indirect prompt injection surface due to processing external project data.
- Ingestion points: Reads
package.jsonand captures the output (stdout,stderr) of executed tests inscripts/test_runner.py. - Boundary markers: Absent; test output is printed directly to the agent's context without clear delimitation.
- Capability inventory: The skill can execute shell commands via
subprocess.runinscripts/test_runner.py. - Sanitization: Absent; the script does not filter or sanitize test output or package metadata before passing it to the agent.
Audit Metadata