test-gap-analysis

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill identifies and executes test commands discovered within project manifests (e.g., dotnet run). This allows for the execution of arbitrary shell commands if the project configuration is untrusted.
  • [DYNAMIC_EXECUTION]: The agent is instructed to apply code mutations—temporary modifications to production source files—and execute the resulting code to verify test effectiveness, which involves runtime modification and execution of program logic.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from the file system (manifests and source code) to derive test boundaries and execution parameters. Ingestion points: Project manifests and source files (SKILL.md). Boundary markers: Absent. Capability inventory: File system write access for mutations and shell command execution for tests (SKILL.md). Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 07:35 AM
Security Audit — agent-trust-hub — test-gap-analysis