ln-55-test-suite-auditor

Warn

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONMETADATA_POISONING
Full Analysis
  • [COMMAND_EXECUTION]: The skill's operational flow explicitly involves using shell commands to run test runners and diagnostic tools found within the target repository.
  • [REMOTE_CODE_EXECUTION]: The agent is instructed to execute "Repository-defined test commands" originating from the audited repository. This allows for the execution of arbitrary code from an untrusted source. While the instructions advise running "only safe" commands, there are no programmatic safeguards to prevent a malicious test suite from executing damaging or unauthorized code.
  • [INDIRECT_PROMPT_INJECTION]: The skill functions as an auditor for external codebases, creating a surface for adversarial content embedded in source code or metadata to influence the agent.
  • Ingestion points: Target repository source code, test definitions, configuration manifests (e.g., package.json), and CI logs.
  • Boundary markers: The instructions provide no specific isolation techniques or delimiters to separate untrusted repository data from the agent's internal control prompt.
  • Capability inventory: The skill leverages shell execution, file system access, and environment inspection tools.
  • Sanitization: No methods for validating or sanitizing the input data or the resulting shell commands are provided.
  • [DATA_EXFILTRATION]: The audit checklist directs the agent to inspect sensitive areas including environment variables, database connections, and network configurations to identify "leakage." An attacker-controlled repository could use these routines to harvest sensitive system information through the shell commands it provides to the agent.
  • [METADATA_POISONING]: The skill description and name repeatedly claim a "read-only" audit and that it "does not edit tests." However, the requirement to "Run representative suites" using shell tools involves active code execution that can have side effects such as creating artifacts, altering network state, or changing local databases, making the "read-only" claim potentially deceptive.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 2, 2026, 01:56 PM
Security Audit — agent-trust-hub — ln-55-test-suite-auditor