fix-tests
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests external data from the project being analyzed (such as project configuration files and test logs) to drive the behavior of its orchestrator and sub-agents.
- Ingestion points: Reads
package.json,README.md, and test output files to identify project structure and test commands. - Boundary markers: The skill lacks explicit delimiters or instructions to ignore embedded commands or malicious instructions within the ingested project files.
- Capability inventory: The skill possesses the ability to execute shell commands (discovered test runners) and modify source code files via sub-agents.
- Sanitization: There is no evidence of validation or sanitization for the discovered commands or the content of the files before they are processed by the agents.
Audit Metadata