sota-testing
Pass
Audited by Gen Agent Trust Hub on Aug 5, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is entirely instructional, containing only markdown documentation and strategy rules without any executable code or automated installation scripts.
- [PROMPT_INJECTION]: File
rules/06-property-fuzzing-mutation.mdcontains a specific security advisory regardingjqwik(versions >= 1.10.0), which includes ANSI-masked prompt-injection payloads (protestware) targeting AI agents. This is an informative defensive warning, not a malicious injection. - [EXTERNAL_DOWNLOADS]: The skill mentions and recommends numerous industry-standard testing tools (e.g., Testcontainers, Pact, Playwright, Hypothesis, Stryker) from trusted ecosystems. It does not contain any direct download or execution commands.
- [DATA_EXFILTRATION]: The instructions explicitly guide the agent to identify and remediate data exposure risks, including hardcoded secrets, production data handling, and lack of network hermeticity in unit tests.
- [COMMAND_EXECUTION]: Provides guidance on using standard developer tools (e.g.,
pytest,go test,find,grep) for auditing and testing purposes, emphasizing best practices and safety.
Audit Metadata