quality-acceptance-testing

Warn

Audited by Gen Agent Trust Hub on Jul 8, 2026

Risk Level: MEDIUMPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Use of repetitive and misleading content in reference files. Multiple files, including 'references/architecture-patterns.md', 'references/code-organization.md', and 'references/state-management.md', contain 150 sections each of identical boilerplate text repetitions. This structure is deceptive as it claims to provide Staff+ level technical specifications while displacement of context via flooding can be used to bypass safety guardrails or displace critical instructions.
  • [PROMPT_INJECTION]: Indirect prompt injection surface via untrusted data ingestion.
  • Ingestion points: The skill workflows describe the ingestion and processing of user-supplied feedback and beta surveys in 'references/beta-program-management.md'.
  • Boundary markers: The instructions do not define delimiters or provide warnings to the agent to isolate natural language feedback from its operational instructions.
  • Capability inventory: The skill enables the execution of test runners such as 'pytest-bdd' and 'cucumber-js' which can execute system commands.
  • Sanitization: No sanitization or filtering logic is specified for processing the content of tester feedback before it enters the agent's decision-making context.
  • [SAFE]: Use of trusted and well-known external service references. The skill includes appropriate references to established platforms for analytics, error tracking, and security scanning (e.g., Mixpanel, Amplitude, Sentry, and Snyk) that are standard in software testing environments.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 8, 2026, 12:26 PM
Security Audit — agent-trust-hub — quality-acceptance-testing