quality-e2e-testing

Warn

Audited by Gen Agent Trust Hub on Jul 8, 2026

Risk Level: MEDIUMPROMPT_INJECTIONEXTERNAL_DOWNLOADSNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: Multiple reference files (including architecture-patterns.md, code-organization.md, deployment-pipelines.md, error-handling.md, performance-optimization.md, security-best-practices.md, state-management.md, and testing-strategies.md) contain approximately 150 sections each of repetitive, auto-generated content.
  • This 'Context Bloat' is characteristic of a token injection attack intended to fill the context window and displace system prompts or safety guardrails.
  • The content is deceptively labeled as 'dense technical specifications' for 'Staff+ Engineers' to encourage the model to prioritize and process the redundant data.
  • [PROMPT_INJECTION]: The SKILL.md file contains specific output control instructions ('No preamble. No postamble. No explanations... No filler... Compress output') designed to minimize transparency and oversight of the agent's actions.
  • [EXTERNAL_DOWNLOADS]: The skill documentation recommends installing standard testing frameworks and tools via legitimate registries (e.g., 'npm init playwright@latest', 'npm install cypress'). These references are to well-known and trusted services.
  • [NO_CODE]: The skill consists entirely of Markdown documentation and code snippets; it does not distribute executable scripts, binaries, or configuration files that could be run directly in the environment.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 8, 2026, 12:26 PM
Security Audit — agent-trust-hub — quality-e2e-testing