test-planner
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill operates by ingesting data from an external file to generate structured documentation and executable test code, which presents an indirect prompt injection surface. Ingestion points: The skill requires an input file, specifically
usecases.md, as defined in the parameters. Boundary markers: There are no explicit instructions or delimiters used to ensure the agent ignores or sanitizes potential commands embedded within the input file. Capability inventory: The skill is designed to write multiple file types (Markdown and TypeScript) to theoutput/pm/directory on the local file system. Sanitization: Input content is interpolated into templates without validation or escaping logic.
Audit Metadata