pytest-optimizer

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [NO_CODE]: The skill package only contains metadata (skill.yaml) and documentation (SKILL.md). There are no implementation scripts, binaries, or executable logic files provided to perform the stated capabilities.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from local Python projects (e.g., requirements.txt, pyproject.toml) via the project_path input. This exposes a vulnerability where the agent might interpret instructions embedded in these files as authoritative commands.
  • Ingestion points: Reads project files specified by the project_path input, specifically mentioning requirements.txt and pyproject.toml in SKILL.md.
  • Boundary markers: None are defined to help the agent distinguish between file content and instructions.
  • Capability inventory: Claims to perform automated analysis and integration with Python tooling.
  • Sanitization: No evidence of input validation, filtering, or escaping of the ingested file content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 08:32 AM
Security Audit — agent-trust-hub — pytest-optimizer