test-driven-development

Pass

Audited by Gen Agent Trust Hub on Mar 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands such as npm test to verify test failures and successes. This capability is central to the skill's purpose of automating TDD workflows. Evidence includes the use of npm test path/to/test.test.ts in the verification steps.
  • Ingestion points: The agent reads and executes local test files (e.g., path/to/test.test.ts) which may be modified by users or external contributors.
  • Boundary markers: No specific boundary markers or safety delimiters for code execution are mentioned.
  • Capability inventory: Subprocess execution is invoked via npm test to run the test suite.
  • Sanitization: No sanitization of the test path or file content is described before execution.
  • [PROMPT_INJECTION]: The skill uses strong imperative language and 'Iron Laws' (e.g., 'Delete it. Start over.', 'No exceptions') to enforce the TDD methodology. While this language is forceful, it is scoped to the specific software development process and does not attempt to bypass core AI safety filters or exfiltrate system prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 4, 2026, 09:52 AM
Security Audit — agent-trust-hub — test-driven-development