pytest-optimizer
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
- [NO_CODE]: The skill package only contains metadata (
skill.yaml) and documentation (SKILL.md). There are no implementation scripts, binaries, or executable logic files provided to perform the stated capabilities. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from local Python projects (e.g.,
requirements.txt,pyproject.toml) via theproject_pathinput. This exposes a vulnerability where the agent might interpret instructions embedded in these files as authoritative commands. - Ingestion points: Reads project files specified by the
project_pathinput, specifically mentioningrequirements.txtandpyproject.tomlinSKILL.md. - Boundary markers: None are defined to help the agent distinguish between file content and instructions.
- Capability inventory: Claims to perform automated analysis and integration with Python tooling.
- Sanitization: No evidence of input validation, filtering, or escaping of the ingested file content.
Audit Metadata