tdd-migrate
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection as it is designed to ingest and process external source code and pattern files.
- Ingestion points: External code located at
<source_path>and specific reference files designated by the<pattern>parameter are read by thescoutandkrakenagents (SKILL.md). - Boundary markers: The instructions do not utilize specific delimiters or explicit 'ignore embedded instructions' directives to safeguard the agent when it processes content from the input files.
- Capability inventory: The orchestration workflow utilizes the
Bashtool to execute tests and quality checks, theWritetool to create or modify files, and theTasktool to spawn sub-agents with these capabilities. - Sanitization: There are no mentioned mechanisms for sanitizing, validating, or filtering the content of the files being read before they are interpolated into prompts or used in subsequent operations.
- [COMMAND_EXECUTION]: The workflow relies on the
Bashtool to perform essential tasks such as running tests (bun test) and quality assurance checks (qlty check). While these operations are necessary for the skill's stated purpose of TDD migration, the execution of shell commands based on the content of external files presents a potential vector for exploitation if those files contain malicious payloads.
Audit Metadata