specialist-testing-testing-evidence-collector

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill defines a skeptical QA persona ('EvidenceCollector') using strong instructional steering in the subagent prompt. These instructions are used to establish a specific behavioral profile for testing tasks rather than attempting to bypass safety filters or override system constraints.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted implementation data and possesses command-execution capabilities, establishing an indirect prompt injection surface.\n
  • Ingestion points: Processes external specifications and implementation details provided as input for QA assessment in the subagent prompt (SKILL.md).\n
  • Boundary markers: The prompt does not utilize explicit delimiters or instructions to ignore potential commands embedded within the analyzed data.\n
  • Capability inventory: The instructions direct the subagent to "Run reality check commands to capture screenshots," which involves executing system-level tools or shell commands.\n
  • Sanitization: No sanitization or validation mechanisms are described for the external content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 08:50 PM
Security Audit — agent-trust-hub — specialist-testing-testing-evidence-collector