regression-test-selection

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill uses instructional language like 'Always read' and 'do not select tests by name alone,' which are standard operational constraints for quality assurance tasks and do not represent attempts to bypass safety filters or override agent identity.
  • [REMOTE_CODE_EXECUTION]: No remote code execution patterns, external scripts, or untrusted downloads are present in the skill files.
  • [DATA_EXFILTRATION]: There are no commands or instructions involving network requests to external domains or access to sensitive credentials files (e.g., .ssh, .aws, .env).
  • [OBFUSCATION]: The content is provided in clear text Markdown and YAML formats with no hidden characters, Base64 encoding, or homoglyph attacks detected.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied data such as 'change diffs' and 'test inventories.' While this presents an ingestion surface, the instructions include explicit 'Input Audit' steps to separate facts from assumptions and require evidence-linked conclusions, which serves as a logical boundary against malicious input data. The severity is categorized as safe given the lack of dangerous capabilities (like shell execution) to exploit.
  • [COMMAND_EXECUTION]: The skill documentation mentions artifacts that can be 'executed,' but contextually refers to manual or automated test execution by the user rather than the agent invoking arbitrary shell commands. No !command`` patterns or subprocess calls were found.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 06:26 AM
Security Audit — agent-trust-hub — regression-test-selection