unit-testing-test-generate

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The CoverageAnalyzer class utilizes subprocess.run to execute test commands provided as input (e.g., pytest, jest). While necessary for gathering coverage data, this creates a vector for command execution if the command string is manipulated.
  • [DATA_EXFILTRATION]: The skill uses open(file_path) to read content from the local file system for analysis. Without strict path validation, this mechanism could be misused to access sensitive system files or configuration data.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted source code to identify test scenarios and generate unit tests without adequate sanitization.
  • Ingestion points: Source code files read via the _analyze_python and other analysis methods in SKILL.md.
  • Boundary markers: Absent; there are no instructions to ignore malicious content or directives embedded in the analyzed source code.
  • Capability inventory: File system access (open), system command execution (subprocess.run), and dynamic code generation for multiple frameworks.
  • Sanitization: Absent; the extracted code structure and metadata are used directly to generate new test scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 12:14 PM
Security Audit — agent-trust-hub — unit-testing-test-generate