test-load

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to perform load testing based on user-supplied inputs (e.g., 'load test this', 'find the breaking point'), creating a surface for indirect prompt injection. Malicious users could supply targets or journey descriptions designed to manipulate the agent's network behavior or tool arguments. While the skill includes behavioral constraints (e.g., avoiding production), it lacks technical input validation.
  • Ingestion points: User-provided targets, authentication methods, and journey definitions described in Phase 0 and Phase 1.
  • Boundary markers: None present to delimit or warn the agent about instructions embedded within user data.
  • Capability inventory: Execution of performance testing tools (k6, Artillery) which are capable of high-volume network traffic generation.
  • Sanitization: The skill does not provide instructions for escaping or validating external content before it is used in test configurations.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 05:56 AM
Security Audit — agent-trust-hub — test-load