awesome-tests
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill provides an attack surface for indirect prompt injection by processing untrusted repository data.
- Ingestion points: The agent is instructed to inspect repository behavior, contracts, callers, nearby tests, framework configuration, and repository commands (SKILL.md, Common workflow).
- Boundary markers: The skill does not provide specific delimiters or instructions to ignore embedded malicious instructions in the files it reads.
- Capability inventory: The agent can execute shell commands to run tests and modify repository code temporarily to prove test sensitivity (SKILL.md, Sensitivity safety and Common workflow).
- Sanitization: There are no explicit requirements for sanitizing or validating repository content before processing.
Audit Metadata