mockable-code
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: Automated scanners identified a potential remote code execution pattern involving a specific URL (
https://payments.example.test/charge) withinscripts/test_skill.py. Analysis shows this is a false positive; the URL is a hardcoded string literal inside a test fixture. This fixture is written to a temporary file solely to verify that the scanner correctly identifies network access patterns and is never actually executed.\n- [COMMAND_EXECUTION]: The skill includes a testing script,scripts/test_skill.py, which utilizessubprocess.runto call internal validation scripts (scripts/validate.pyandscripts/analyze_mockability.py). These commands are standard for automated testing, are scoped to the skill's own directory, and do not incorporate external or unsanitized inputs.\n- [INDIRECT_PROMPT_INJECTION]: Thescripts/analyze_mockability.pyscript accepts user-specified directory paths and reads source files to identify hardcoded dependencies. While this constitutes an ingestion surface for potentially untrusted content, the script only performs regex-based scanning and console reporting. It does not execute the files or pass their content to high-privilege functions.
Audit Metadata