qa-test-planner

Warn

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The interactive bash scripts scripts/create_bug_report.sh and scripts/generate_test_cases.sh contain a command injection vulnerability. The prompt_input function uses the eval command to dynamically assign user-provided input to variable names. This allows a user (or the AI agent if directed by malicious data) to execute arbitrary shell commands by including shell metacharacters like semicolons, backticks, or command substitution syntax ($()) in their response to script prompts.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it is designed to ingest and parse untrusted data such as feature descriptions and requirements to generate test documentation.
  • Ingestion points: Feature descriptions, requirements, and Figma URLs are processed during the Analyze Phase as defined in README.md and SKILL.md.
  • Boundary markers: There are no clear boundary markers or instructions to the AI agent to ignore embedded commands within the ingested data across the provided templates.
  • Capability inventory: The skill has the capability to execute shell scripts and write to the local file system, providing a path for an injection to cause side effects.
  • Sanitization: There is no evidence of sanitization or validation of the external content before it is processed by the agent or passed to the vulnerable bash scripts.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 29, 2026, 02:05 AM
Security Audit — agent-trust-hub — qa-test-planner