qe-consultancy-practices

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill consists of instructional content and pseudo-code examples for software quality consultancy. The instructions focus on methodology, communication, and strategy, which are inherently safe.
  • [INDIRECT_PROMPT_INJECTION]: The documentation identifies a workflow that ingests content from external directories for automated assessment. This represents a potential surface for indirect prompt injection if the files within the analyzed codebase contain instructions targeted at the agent.
  • Ingestion points: The skill describes analyzing the client-project/ directory in the Agent Integration section.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded content are defined in the provided pseudo-code examples.
  • Capability inventory: The documented capabilities include automated codebase analysis, ROI calculations, and fleet coordination of multiple quality analysis agents.
  • Sanitization: The high-level methodology does not specify sanitization or validation steps for ingested file content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 06:15 PM
Security Audit — agent-trust-hub — qe-consultancy-practices