qa-test-planner
Warn
Audited by Gen Agent Trust Hub on Mar 29, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The interactive bash scripts
scripts/create_bug_report.shandscripts/generate_test_cases.shcontain a command injection vulnerability. Theprompt_inputfunction uses theevalcommand to dynamically assign user-provided input to variable names. This allows a user (or the AI agent if directed by malicious data) to execute arbitrary shell commands by including shell metacharacters like semicolons, backticks, or command substitution syntax ($()) in their response to script prompts. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it is designed to ingest and parse untrusted data such as feature descriptions and requirements to generate test documentation.
- Ingestion points: Feature descriptions, requirements, and Figma URLs are processed during the Analyze Phase as defined in
README.mdandSKILL.md. - Boundary markers: There are no clear boundary markers or instructions to the AI agent to ignore embedded commands within the ingested data across the provided templates.
- Capability inventory: The skill has the capability to execute shell scripts and write to the local file system, providing a path for an injection to cause side effects.
- Sanitization: There is no evidence of sanitization or validation of the external content before it is processed by the agent or passed to the vulnerable bash scripts.
Audit Metadata