testing
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references the
hardhat-exposedplugin hosted on GitHub, which is used to generate test wrappers for internal contract functions. This is a standard tool within the OpenZeppelin ecosystem. - [COMMAND_EXECUTION]: Includes instructions for running various development and testing commands such as
npm test,npx changeset,make -C fv apply, and customnodescripts for triggering Certora formal verification specs. - [INDIRECT_PROMPT_INJECTION]: The skill requires the agent to process and write tests for smart contract source code, creating a vulnerability surface for indirect prompt injection if the source files contain malicious instructions.
- Ingestion points: Reads contract source code from
contracts/and test specifications fromtest/andfv/specs/. - Boundary markers: No explicit instructions are provided to delimit or ignore potential instructions embedded within the contract data.
- Capability inventory: The skill allows execution of shell commands for testing, linting, and formal verification.
- Sanitization: No specific content sanitization or validation logic is defined for the smart contract inputs.
Audit Metadata