specialist-testing-testing-reality-checker
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external sources such as 'QA findings' and 'system claims', which constitutes a vulnerability surface for indirect prompt injection.
- Ingestion points: Data enters the agent context through 'QA findings', 'claimed features', and 'previous agent' reports mentioned in
SKILL.md. - Boundary markers: Absent; the skill does not specify delimiters or instructions to ignore embedded commands within the ingested content.
- Capability inventory: The subagent prompt in
SKILL.mdimplies access to 'automated tools' for screenshots and 'reality check commands'. - Sanitization: Absent; there are no instructions to sanitize, escape, or validate the findings from other agents or tools.
- [PROMPT_INJECTION]: The subagent instructions in
SKILL.mduse strong directives such as 'Stop Fantasy Approvals' and 'Default to FAILED'. These are evaluated as domain-specific persona constraints for a testing role rather than malicious overrides of the system's core safety filters.
Audit Metadata