test-driven-development
Pass
Audited by Gen Agent Trust Hub on Mar 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands such as
npm testto verify test failures and successes. This capability is central to the skill's purpose of automating TDD workflows. Evidence includes the use ofnpm test path/to/test.test.tsin the verification steps. - Ingestion points: The agent reads and executes local test files (e.g.,
path/to/test.test.ts) which may be modified by users or external contributors. - Boundary markers: No specific boundary markers or safety delimiters for code execution are mentioned.
- Capability inventory: Subprocess execution is invoked via
npm testto run the test suite. - Sanitization: No sanitization of the test path or file content is described before execution.
- [PROMPT_INJECTION]: The skill uses strong imperative language and 'Iron Laws' (e.g., 'Delete it. Start over.', 'No exceptions') to enforce the TDD methodology. While this language is forceful, it is scoped to the specific software development process and does not attempt to bypass core AI safety filters or exfiltrate system prompts.
Audit Metadata