aqe-test-change
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill reads and processes external code changes and documentation, which constitutes an ingestion point for potentially malicious instructions embedded in the data. * Ingestion points: The skill reads changed code and nearby tests as defined in SKILL.md. * Boundary markers: There are no specific instructions or delimiters provided to the agent to distinguish code from instructions. * Capability inventory: The skill is authorized to run Vitest targets, builds, and MCP integration checks, providing a path for command execution. * Sanitization: No input validation or sanitization of the analyzed code is mentioned.
- [COMMAND_EXECUTION]: The skill directs the agent to execute software testing and build commands such as Vitest and typechecking. This is the intended behavior for the skill's primary purpose and is necessary for its operation.
Audit Metadata