testing
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill facilitates the execution of local development tools and scripts as part of its primary TDD workflow.
- Evidence: References to
pnpm test,pnpm check,go test, and the execution of a local scaffolding script located at./scripts/scaffold-fixture.sh. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from external fixture files, representing a theoretical surface for indirect prompt injection if the project's test data is untrusted.
- Ingestion points: Data is read from files within the
testdata/directory, includinginput.json,input.ndjson, andexpected.mdas described inreferences/fixtures.md. - Boundary markers: No explicit delimiters or instructions to ignore embedded content are specified when the agent reads these files.
- Capability inventory: The skill utilizes
pnpm,go test, shell script execution, and acommittool to perform its tasks. - Sanitization: No content sanitization or validation logic is defined for the fixture data within the skill instructions.
- Mitigation: The skill documentation describes a
source_hashintegrity mechanism in theexpected.mdfrontmatter, which is maintained by thepnpm fixtures:hash:synccommand to detect unauthorized changes to test inputs.
Audit Metadata