maintainable-tests
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill represents legitimate development documentation and utility code. No malicious instructions or hidden behaviors were detected across the SKILL.md or supporting scripts.
- [COMMAND_EXECUTION]: The utility script scripts/test_skill.py uses subprocess.run to execute the skill's scanner for internal testing. This usage is not exposed to arbitrary user input and follows best practices for safe process spawning.
- [INDIRECT_PROMPT_INJECTION]: The scanner script scripts/analyze_maintainable_tests.py reads external code files (Ingestion point: read_source). While boundary markers are absent in the prompt, the script limits risk through resource constraints and a mask_source function that sanitizes content by masking comments and strings before regex analysis. The skill's capabilities are limited to local file reading and internal tool execution (subprocess.run in scripts/test_skill.py).
Audit Metadata