skills/poteto/noodle/testing/Gen Agent Trust Hub

testing

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill facilitates the execution of local development tools and scripts as part of its primary TDD workflow.
  • Evidence: References to pnpm test, pnpm check, go test, and the execution of a local scaffolding script located at ./scripts/scaffold-fixture.sh.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external fixture files, representing a theoretical surface for indirect prompt injection if the project's test data is untrusted.
  • Ingestion points: Data is read from files within the testdata/ directory, including input.json, input.ndjson, and expected.md as described in references/fixtures.md.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded content are specified when the agent reads these files.
  • Capability inventory: The skill utilizes pnpm, go test, shell script execution, and a commit tool to perform its tasks.
  • Sanitization: No content sanitization or validation logic is defined for the fixture data within the skill instructions.
  • Mitigation: The skill documentation describes a source_hash integrity mechanism in the expected.md frontmatter, which is maintained by the pnpm fixtures:hash:sync command to detect unauthorized changes to test inputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 03:00 AM