qa-expert
Fail
Audited by Gen Agent Trust Hub on Mar 22, 2026
Risk Level: HIGHPROMPT_INJECTIONCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill utilizes 'Master Prompts' in
references/master_qa_prompt.mdandreferences/llm_prompts_library.mdthat employ persona adoption ('senior QA engineer with 20+ years of experience at Google') and imperative directives ('CRITICAL INSTRUCTIONS', 'MANDATORY RULES') designed to hijack agent behavior and bypass default constraints.\n- [COMMAND_EXECUTION]: The onboarding guide inreferences/day1_onboarding.mdcontains explicit instructions to achieve persistence on the host system by modifying shell profile files such as~/.bashrcand~/.zshrcto include persistent environment variable changes.\n- [REMOTE_CODE_EXECUTION]: The skill directs users to execute commands likegit cloneandpnpm installfrom unverified external sources inreferences/day1_onboarding.md, which can lead to the execution of malicious code during the environment setup process.\n- [PROMPT_INJECTION]: The autonomous execution workflow establishes an indirect prompt injection surface by instructing the agent to read and 'execute all steps exactly as documented' from external Markdown files (e.g.,02-CLI-TEST-CASES.md). This process lacks sanitization, validation, or boundary markers, allowing a compromised test case file to execute arbitrary system commands via the agent's available tools.
Recommendations
- AI detected serious security threats
Audit Metadata