skills/parcha-ai/parcha-skills/autoqa/Gen Agent Trust Hub

autoqa

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill automates the execution of arbitrary shell commands found in a target repository's configuration and runbooks, such as Makefiles, Dockerfiles, and Procfiles. This capability is used to boot the application for testing purposes. Evidence: Phase 3 (Execution) instructs the agent to 'respect the repo's own runbook... over generic docker commands' when bringing the application instance up.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it is designed to ingest and follow instructions from untrusted repository files to determine its execution and testing strategy. Mandatory Evidence Chain: 1. Ingestion points: Target repository files including CLAUDE.md, AGENTS.md, .cursorrules, and AUTOQA.md (specified in SKILL.md Phase 1 and references/discovery.md). 2. Boundary markers: None; the instructions do not require the agent to use delimiters or ignore instructions found within these discovered files. 3. Capability inventory: The agent has capabilities for shell command execution (Phase 3), network operations via curl and UI tools (Phase 2), and file system writes (Phase 3 reporting). 4. Sanitization: No sanitization or validation of the discovered instructions is performed before they are acted upon.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 03:13 AM
Security Audit — agent-trust-hub — autoqa