generate-tdd-tasks
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data such as feature descriptions and PRDs to generate task lists. This creates a surface where malicious instructions in the source text could influence the generated output.
- Ingestion points: Requirements, PRDs, and feature descriptions (SKILL.md Step 2).
- Boundary markers: None identified.
- Capability inventory: File write operations to create task files in the tasks/ directory (SKILL.md Step 3).
- Sanitization: No specific sanitization or escaping of input content is mentioned.
- [COMMAND_EXECUTION]: The skill generates shell commands for branch creation and test execution (e.g., git checkout, npm test) as part of the TDD workflow. These are standard development tasks and do not represent a security risk in this context.
Audit Metadata