test-generator

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external source code, API definitions, and existing test patterns to generate new tests. This functionality creates an attack surface for indirect prompt injection, where malicious instructions embedded in the target code could influence the agent's behavior.
  • Ingestion points: The skill instructions in SKILL.md (Step 2: Analyze Target Code and Step 3: Analyze Test Patterns) direct the agent to read component code, functions, and existing test files using Read, Glob, and Grep tools.
  • Boundary markers: There are no instructions or delimiters provided to isolate the ingested code content from the agent's internal instructions, increasing the likelihood that the agent might follow instructions embedded within the data.
  • Capability inventory: The skill utilizes Read, Write, Glob, and Grep tools, which allow it to discover and modify files throughout the workspace based on its analysis.
  • Sanitization: No sanitization, validation, or filtering of the ingested code content is performed before the agent processes it for test generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 01:45 PM
Security Audit — agent-trust-hub — test-generator