test-gap-analysis
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill identifies and executes test commands discovered within project manifests (e.g.,
dotnet run). This allows for the execution of arbitrary shell commands if the project configuration is untrusted. - [DYNAMIC_EXECUTION]: The agent is instructed to apply code mutations—temporary modifications to production source files—and execute the resulting code to verify test effectiveness, which involves runtime modification and execution of program logic.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from the file system (manifests and source code) to derive test boundaries and execution parameters. Ingestion points: Project manifests and source files (SKILL.md). Boundary markers: Absent. Capability inventory: File system write access for mutations and shell command execution for tests (SKILL.md). Sanitization: Absent.
Audit Metadata