common-tdd

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process code and test files, which constitutes a surface for indirect prompt injection where instructions could be hidden in processed data.\n
  • Ingestion points: Test and specification files defined in the metadata triggers (e.g., **/.test.ts, **/_test.go, **/Test.java, **/_test.dart, **/*_spec.rb).\n
  • Boundary markers: The protocol requires generating a 'Test Intent Record' to document observable contracts and faults before execution, acting as a logical constraint before any commands are run.\n
  • Capability inventory: The skill involves executing various test runners (Vitest, Go test, Maven, Gradle, Flutter) as subprocesses to verify code changes, as described in references/test_runners.md.\n
  • Sanitization: The skill enforces robust execution safety guidelines in SKILL.md and references/quality-contract.md, including 120-second fallback timeouts, sequential single-run mode, and targeted process group termination to ensure environment isolation and stability.\n- [SAFE]: The skill instructions and reference materials promote standard industry best practices for quality-first TDD. No evidence of obfuscation, hardcoded credentials, persistence mechanisms, or unauthorized network activity was found.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 05:45 PM
Security Audit — agent-trust-hub — common-tdd