test-completed-plan

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes shell commands for starting the target application and running testing frameworks (e.g., pytest, vitest) as defined in the automated-testing-instructions.md configuration file.- [INDIRECT_PROMPT_INJECTION]: The skill ingests instructions from external project files which influences its execution behavior.
  • Ingestion points: Processes testing checklists and commands from meta/specs/NNN-*/spec.md and meta/workflows/automated-testing/automated-testing-instructions.md.
  • Boundary markers: None identified; the instructions are treated as trusted directives for the testing process.
  • Capability inventory: Includes shell command execution, browser automation via CDP, read-only database queries, and temporary application source code modification.
  • Sanitization: No explicit sanitization or validation of the commands or steps provided in the configuration files is described.- [DYNAMIC_EXECUTION]: The skill performs 'temp instrumentation' by programmatically editing the application's source code at runtime to enable observability (e.g., logging payload bodies), followed by a mandatory cleanup step to restore the repository state.- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill implements safety best practices for handling sensitive data, specifically instructing the agent to never commit or leak authentication tokens, cookies, or secrets, and requiring the redaction of such information from logs and artifacts.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 09:06 AM
Security Audit — agent-trust-hub — test-completed-plan