sota-testing

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is entirely instructional, containing only markdown documentation and strategy rules without any executable code or automated installation scripts.
  • [PROMPT_INJECTION]: File rules/06-property-fuzzing-mutation.md contains a specific security advisory regarding jqwik (versions >= 1.10.0), which includes ANSI-masked prompt-injection payloads (protestware) targeting AI agents. This is an informative defensive warning, not a malicious injection.
  • [EXTERNAL_DOWNLOADS]: The skill mentions and recommends numerous industry-standard testing tools (e.g., Testcontainers, Pact, Playwright, Hypothesis, Stryker) from trusted ecosystems. It does not contain any direct download or execution commands.
  • [DATA_EXFILTRATION]: The instructions explicitly guide the agent to identify and remediate data exposure risks, including hardcoded secrets, production data handling, and lack of network hermeticity in unit tests.
  • [COMMAND_EXECUTION]: Provides guidance on using standard developer tools (e.g., pytest, go test, find, grep) for auditing and testing purposes, emphasizing best practices and safety.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 10:17 PM
Security Audit — agent-trust-hub — sota-testing