testing-workflow
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides documentation and commands for running test suites and CI gates using standard tools like pnpm and vitest within the repository context.
- [COMMAND_EXECUTION]: The instructions include commands for executing project-specific tests (e.g., pnpm test:capabilities, pnpm test:byok). These operations are routine for code validation and repository maintenance.
- [DYNAMIC_EXECUTION]: The skill references local scripts such as scripts/verify.mjs and scripts/source-inventory.mjs for repository verification and inventory management, representing standard development behavior.
- [INDIRECT_PROMPT_INJECTION]: The workflow involves reading repository documentation and changed files (ingestion points) to determine test scope. While boundary markers and sanitization are not explicitly defined, the capability inventory (pnpm, node, git) is restricted to standard verification protocols within the repository context.
Audit Metadata