tdd

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill orchestrates the use of standard Elixir development tools such as mix test, mix format, mix credo, and mix dialyzer. These are legitimate commands used for automated testing, formatting, and static analysis within Elixir projects.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it is designed to ingest and process external data (Elixir source code and test files) which is then used to influence agent actions.
  • Ingestion points: Reads local project files (.ex and .exs) during the TDD cycle as described in Phase 1 and Phase 4.
  • Boundary markers: None explicitly defined in the instructions to separate untrusted code content from agent instructions.
  • Capability inventory: Executes shell commands via the mix build tool across multiple phases.
  • Sanitization: No sanitization or validation of the ingested code content is performed before the agent processes it.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 05:28 AM
Security Audit — agent-trust-hub — tdd