testing-patterns

Warn

Audited by Gen Agent Trust Hub on Mar 18, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The scripts/test_runner.py script uses subprocess.run to execute system-level test commands like npm test and pytest. This functionality relies on the integrity of the project configuration files, as it will execute whatever is defined in the project's test scripts.
  • [REMOTE_CODE_EXECUTION]: The script utilizes npx to execute tools like Vitest and Jest. npx is designed to download and run packages from the npm registry if they are not present locally, which serves as a vector for remote code execution.
  • [EXTERNAL_DOWNLOADS]: Test execution via npm or npx typically involves downloading dependencies or binaries from external package registries such as NPM or PyPI.
  • [PROMPT_INJECTION]: The test runner represents an indirect prompt injection surface as its control flow is dictated by untrusted data in local project files.
  • Ingestion points: The detect_test_framework function in scripts/test_runner.py reads data from package.json, pyproject.toml, and requirements.txt.
  • Boundary markers: None; the script assumes the project files are well-formed and standard.
  • Capability inventory: The script possesses the capability to execute shell commands and read/write files within the agent's environment.
  • Sanitization: No sanitization or validation of the values read from the configuration files is performed before they are used to select command strings for execution.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 18, 2026, 07:46 AM
Security Audit — agent-trust-hub — testing-patterns