specialist-engineering-test-writer-fixer

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The sub-agent is instructed to execute shell commands using various test runners such as Jest, Pytest, Mocha, and PHPUnit to identify affected files and verify code changes.\n- [PROMPT_INJECTION]: The skill interpolates the raw user input {the user's question} directly into the prompt for the sub-agent. This lack of boundary markers (e.g., XML tags or clear delimiters) creates a surface for indirect prompt injection where a user could potentially supply instructions that override the agent's defined behavior.\n
  • Ingestion points: Interpolation into the sub-agent prompt in SKILL.md.\n
  • Boundary markers: Absent.\n
  • Capability inventory: File system modification (writing tests) and shell command execution (running tests).\n
  • Sanitization: None observed in the static definition.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 08:50 PM
Security Audit — agent-trust-hub — specialist-engineering-test-writer-fixer