test-planner

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill operates by ingesting data from an external file to generate structured documentation and executable test code, which presents an indirect prompt injection surface. Ingestion points: The skill requires an input file, specifically usecases.md, as defined in the parameters. Boundary markers: There are no explicit instructions or delimiters used to ensure the agent ignores or sanitizes potential commands embedded within the input file. Capability inventory: The skill is designed to write multiple file types (Markdown and TypeScript) to the output/pm/ directory on the local file system. Sanitization: Input content is interpolated into templates without validation or escaping logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 08:27 PM
Security Audit — agent-trust-hub — test-planner