add-product-e2e-eval

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill requires the execution of shell commands using pnpm and git to manage the testing lifecycle, including repository location, type checking, unit testing, and running end-to-end evaluation suites.
  • [INDIRECT_PROMPT_INJECTION]: A vulnerability surface exists where the agent ingests data from external sources and local repository files while holding capabilities to modify source code and execute commands.
  • Ingestion points: The agent reads existing repository documentation (e.g., README.md, FIXTURES.md, doc/evals.md) and interacts with external browser/API surfaces, including capturing screenshots and logs from production-like environments.
  • Boundary markers: There are no specific delimiters or instructions provided to isolate processed data from the agent's core instructions, potentially allowing embedded data to influence agent behavior.
  • Capability inventory: The agent has the authority to write new test cases and registration code to files such as catalog.ts and fixture-registry.ts, and can execute shell commands via pnpm as part of the test verification process.
  • Sanitization: Although the instructions advise sanitizing public fixtures and screenshots, there are no technical enforcement mechanisms or specific sanitization routines defined for the data processed during execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 09:07 AM
Security Audit — agent-trust-hub — add-product-e2e-eval