skills/jpcaparas/skills/mockable-code/Gen Agent Trust Hub

mockable-code

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: Automated scanners identified a potential remote code execution pattern involving a specific URL (https://payments.example.test/charge) within scripts/test_skill.py. Analysis shows this is a false positive; the URL is a hardcoded string literal inside a test fixture. This fixture is written to a temporary file solely to verify that the scanner correctly identifies network access patterns and is never actually executed.\n- [COMMAND_EXECUTION]: The skill includes a testing script, scripts/test_skill.py, which utilizes subprocess.run to call internal validation scripts (scripts/validate.py and scripts/analyze_mockability.py). These commands are standard for automated testing, are scoped to the skill's own directory, and do not incorporate external or unsanitized inputs.\n- [INDIRECT_PROMPT_INJECTION]: The scripts/analyze_mockability.py script accepts user-specified directory paths and reads source files to identify hardcoded dependencies. While this constitutes an ingestion surface for potentially untrusted content, the script only performs regex-based scanning and console reporting. It does not execute the files or pass their content to high-privilege functions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 03:19 AM
Security Audit — agent-trust-hub — mockable-code