add-test-coverage

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses standard command-line tools such as npm, npx, pytest, and go test to generate coverage reports and run test suites. These commands are executed to verify the behavior of the code and the validity of the new tests.
  • [INDIRECT_PROMPT_INJECTION]: The skill reads existing source code and test files to identify logic and follow project patterns, which constitutes an ingestion point for untrusted data that could contain adversarial instructions.
  • Ingestion points: Processes existing production code and test modules in the repository to understand logic and patterns (Steps 2 and 4).
  • Boundary markers: No specific delimiters or instructions to ignore embedded instructions in the source code are mentioned.
  • Capability inventory: The skill is capable of writing new test files to the local file system and executing shell commands through various test runners (Steps 5, 6, and 7).
  • Sanitization: There are no explicit sanitization or filtering steps mentioned for the content read from the source files before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 11:12 AM
Security Audit — agent-trust-hub — add-test-coverage