qa-expert
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues detected. The skill follows established software testing practices and uses standard Python libraries for local data processing and file management. It includes clear documentation and guidelines for environment setup and project management.
- [INDIRECT_PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection because it is designed for an agent to read and execute instructions from externally provided markdown and CSV files. This is an inherent design feature for a QA automation tool and is mitigated by the 'Ground Truth Principle' documented within the skill.
- Ingestion points:
TEST-EXECUTION-TRACKING.csvand markdown test case documents referenced by theMASTER-QA-PROMPT.md. - Boundary markers: None explicitly defined in the provided prompt templates.
- Capability inventory: The autonomous execution prompt allows the agent to perform environment setup, shell command execution, and file system updates based on the content of test cases.
- Sanitization: No explicit sanitization or filtering of test case content is performed by the provided scripts.
- [COMMAND_EXECUTION]: The skill provides scripts (
init_qa_project.pyandcalculate_metrics.py) that perform local file operations and execution. These scripts are benign and provide the core functionality of the skill. TheMASTER-QA-PROMPT.mdinstructs the agent to execute shell commands during the testing phase, which is the intended primary use-case for this tool.
Audit Metadata