coverage
Pass
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill performs legitimate analysis of local source code and test files to determine coverage gaps, which is consistent with its stated purpose.
- [PROMPT_INJECTION]: The skill is subject to indirect prompt injection because it processes external project data. 1. Ingestion points: Source code files including route definitions, components, and API controllers, along with test files, are scanned via the Explore subagent as defined in SKILL.md. 2. Boundary markers: The instructions lack explicit delimiters or guardrails to prevent the agent from following instructions embedded in the code it reads. 3. Capability inventory: The skill has read access to the filesystem and the ability to trigger test generation via the /pw:generate tool. 4. Sanitization: No sanitization or validation of the ingested code content is performed before processing. This vulnerability surface is inherent to the tool's function and does not constitute a malicious finding.
Audit Metadata