qa-execution
Pass
Audited by Gen Agent Trust Hub on Jul 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides the agent with instructions and authority to modify local source code files through an 'auto-fix' mechanism (Step 7 and fix-loop.md).
- [PROMPT_INJECTION]: The skill is designed to ingest data from external product interfaces, creating a surface for indirect prompt injection.
- Ingestion points: Product UI, API responses, and outputs from agentic products (e.g., chatbots) under test.
- Boundary markers: The skill uses role-play (personas) but lacks explicit prompts to ignore or delimit instructions embedded within the product data it analyzes.
- Capability inventory: Local file modification (source code), browser automation, and CLI execution.
- Sanitization: No specific sanitization or validation steps are prescribed for data received from the external product interfaces before it is processed by the agent.
Audit Metadata