SpecFlow BDD Testing
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external Gherkin feature files (.feature) and user-provided C# test code, which constitute an untrusted data ingestion surface that could be used for indirect prompt injection.
- Ingestion points: The agent is instructed to write, review, and debug Gherkin feature files and step definition code provided by the user.
- Boundary markers: The instructions lack explicit boundary markers or directives to ensure the agent ignores natural language instructions that might be maliciously embedded within the feature files.
- Capability inventory: The skill facilitates the use of Selenium WebDriver for browser automation, HttpClient for network requests, and the dotnet CLI for executing tests and installing tools, providing a path for external interactions.
- Sanitization: There are no mechanisms described for sanitizing or validating the content of feature files before the agent processes them.
Audit Metadata