qe-risk-based-testing
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's instructions and code snippets strictly pertain to quality engineering processes, risk calculation, and test prioritization. No indicators of prompt injection, data exfiltration, or persistence were found.
- [REMOTE_CODE_EXECUTION]: No remote code execution patterns or unauthorized downloads from external sources were detected. The TypeScript snippets are illustrative of inter-agent task delegation using the platform's Task API.
- [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for processing external data such as file change lists and bug databases. This is a primary function of a risk-based testing agent and does not involve dangerous capabilities or lack of sanitization that would warrant a higher severity.
- [COMMAND_EXECUTION]: The CI/CD examples use standard GitHub Actions and npm commands consistent with professional development workflows. No shell injection or arbitrary command execution was identified.
Audit Metadata