test-driven-development

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists of purely instructional content aimed at improving software development practices through TDD. It utilizes standard local development tools and commands, such as bin/rails test, which are consistent with its primary purpose and represent standard engineering workflows.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external requirements and code to generate and run tests. While this creates an ingestion surface for potential indirect prompt injection, it is an inherent and necessary part of a developer tool. No high-risk capabilities or lack of safeguards were found that would escalate this beyond a baseline risk factor.
  • Ingestion points: The agent ingests user-provided feature descriptions, bug reports, and code files to fulfill the TDD requirements described in SKILL.md.
  • Boundary markers: None explicitly defined within the skill's instructions.
  • Capability inventory: Execution of local test runners (bin/rails test) as documented in SKILL.md.
  • Sanitization: Not present within the provided markdown instructions, as the skill focuses on the logical workflow rather than input validation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 11:20 PM
Security Audit — agent-trust-hub — test-driven-development