tester-breaker

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • Command Execution via Shell: The skill utilizes shell environments (e.g., Bash) to execute test inputs against code to verify failures. While essential for its adversarial testing role, this practice involves executing commands that interact with the local environment.- Indirect Prompt Injection Surface: The skill is designed to process and analyze external code and data, which introduces a potential surface for indirect prompt injection findings.
  • Ingestion points: External data enters the context through Read, Grep, and Glob operations performed during the code review process (SKILL.md).
  • Boundary markers: There are no explicit instructions for using delimiters or boundary markers to isolate analyzed code from the agent's instructions.
  • Capability inventory: The skill possesses file system access and shell execution capabilities through Bash to validate its findings.
  • Sanitization: The instructions do not include specific patterns for sanitizing or filtering the content of the files being reviewed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 04:27 AM
Security Audit — agent-trust-hub — tester-breaker