testing-strategies

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to install various testing libraries via npm and pip. These packages (e.g., jest, vitest, pytest, pytest-cov, supertest) are well-known, industry-standard tools for software testing and are fetched from official package registries.
  • [COMMAND_EXECUTION]: The documentation includes standard shell commands for managing test suites, such as copying configuration files, installing dependencies, and running tests (e.g., npm test, pytest, npx vitest). These are routine development workflows and use standard tools.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external context such as service architectures and component code to generate or run tests, which represents an inherent attack surface for coding agents.
  • Ingestion points: Ingests architectural context and source code from other skills (backend, frontend, api-design, database) as defined in the SKILL.md frontmatter.
  • Boundary markers: No explicit boundary markers or instructions to ignore embedded directives are specified in the provided templates.
  • Capability inventory: Capable of writing files to the local filesystem and executing shell commands for package management and test execution as shown in templates/README.md.
  • Sanitization: No specific input sanitization for user-provided code or specifications is defined.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 02:47 PM
Security Audit — agent-trust-hub — testing-strategies