test-driven-development

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute npm test to verify code behavior during the 'Red' and 'Green' phases of the TDD cycle. This is an expected and documented functionality for a development-focused skill.
  • [PROMPT_INJECTION]: The skill employs strong behavioral constraints, such as 'The Iron Law' and instructions to 'Delete and start over' if TDD is not followed. While these are strict directives for the agent's logic, they are pedagogical in nature and intended to enforce a specific coding methodology rather than to bypass safety guardrails or extract sensitive information.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface due to its interaction with user-provided code and tests:
  • Ingestion points: The agent ingests user-provided source code and test files to perform analysis and execute tests (SKILL.md).
  • Boundary markers: None. The instructions do not specify how to distinguish user-provided data from skill instructions during execution.
  • Capability inventory: The agent is authorized to execute shell commands (npm test) and follows instructions for file modification/deletion as part of the TDD workflow (SKILL.md).
  • Sanitization: None. The skill does not explicitly describe sanitization of code before it is passed to the test runner.
  • [SAFE]: No malicious patterns, such as unauthorized network requests, credential harvesting, or obfuscated content, were detected. The skill's external references point to internal project files, and its methodology aligns with standard software engineering practices.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 08:28 PM
Security Audit — agent-trust-hub — test-driven-development