tdd
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is focused on software engineering best practices and documentation. No indicators of prompt injection, data exfiltration, or unauthorized command execution were found in the provided files.
- [INDIRECT_PROMPT_INJECTION]: The skill uses external issue files (
issues/NNN-*.md) to define project goals and acceptance criteria. This represents an indirect prompt injection surface as the agent is instructed to read and act upon content from these files. - Ingestion points:
issues/NNN-*.md,CONTEXT.md, anddocs/REQUIREMENTS-AND-NOTES.md. - Boundary markers: The instructions do not specify any explicit boundary markers or instructions to treat data within these artifacts as untrusted.
- Capability inventory: The skill instructions involve reading existing project files and writing implementation code, tests, and updates to issue files.
- Sanitization: No sanitization or validation logic is specified for the content processed from these external artifacts.
Audit Metadata