qa-execution

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides the agent with instructions and authority to modify local source code files through an 'auto-fix' mechanism (Step 7 and fix-loop.md).
  • [PROMPT_INJECTION]: The skill is designed to ingest data from external product interfaces, creating a surface for indirect prompt injection.
  • Ingestion points: Product UI, API responses, and outputs from agentic products (e.g., chatbots) under test.
  • Boundary markers: The skill uses role-play (personas) but lacks explicit prompts to ignore or delimit instructions embedded within the product data it analyzes.
  • Capability inventory: Local file modification (source code), browser automation, and CLI execution.
  • Sanitization: No specific sanitization or validation steps are prescribed for data received from the external product interfaces before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 12:15 PM
Security Audit — agent-trust-hub — qa-execution