qe-risk-based-testing

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's instructions and code snippets strictly pertain to quality engineering processes, risk calculation, and test prioritization. No indicators of prompt injection, data exfiltration, or persistence were found.
  • [REMOTE_CODE_EXECUTION]: No remote code execution patterns or unauthorized downloads from external sources were detected. The TypeScript snippets are illustrative of inter-agent task delegation using the platform's Task API.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for processing external data such as file change lists and bug databases. This is a primary function of a risk-based testing agent and does not involve dangerous capabilities or lack of sanitization that would warrant a higher severity.
  • [COMMAND_EXECUTION]: The CI/CD examples use standard GitHub Actions and npm commands consistent with professional development workflows. No shell injection or arbitrary command execution was identified.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 06:15 PM
Security Audit — agent-trust-hub — qe-risk-based-testing