test-audit
Pass
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill guides the agent to execute standard, repository-local test runners and coverage tools including Vitest, Jest, c8, pytest, and Go. These commands are necessary for the skill's stated purpose of validating test deletions against a coverage budget.
- [DYNAMIC_EXECUTION]: A utility script in
references/coverage.mdusesnode -eto execute a JavaScript snippet that compares JSON coverage reports. The script usesrequireto load local JSON files for calculation, which is a standard procedure for this type of tool. - [INDIRECT_PROMPT_INJECTION]: The skill operates on repository source code and test files, which constitutes a surface for indirect prompt injection.
- Ingestion points: The agent reads production code and test files to identify "junk patterns."
- Boundary markers: The instructions do not specify the use of delimiters or specific headers to isolate untrusted code content from instructions.
- Capability inventory: The skill has the capability to delete files within the repository and execute shell commands for testing.
- Sanitization: There is no explicit sanitization of the code being read, though the skill focuses on structural analysis of assertions rather than executing the code logic directly.
Audit Metadata