test-driven-development

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Behavioral Overrides: The skill employs absolute and imperative language, such as "The Iron Law," "Final Rule," and "No exceptions," to enforce a rigid workflow. It specifically commands the agent to delete its own production code if a test was not written first, which acts as a behavioral override of the agent's primary code-generation function.
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface: The skill is intended to be active when the agent processes untrusted user-provided data, such as feature requests and bug descriptions. It lacks explicit instructions for using boundary markers or sanitizing this input. * Ingestion points: User-provided requirement descriptions for features and bugs in SKILL.md. * Boundary markers: Not present in the skill instructions. * Capability inventory: Execution of test commands (npm test) and management of the project's source code files. * Sanitization: Not present.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 07:46 AM