qe-xp-practices
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill documents orchestration patterns that ingest untrusted data from external sources.\n- Ingestion points: The 'Agent Integration' section in SKILL.md suggests using variables such as 'charter' (user input) and 'prDiff' (git repository content) within agent tasks.\n- Boundary markers: No specific delimiters or safety instructions are defined in the orchestration examples to isolate the untrusted data.\n- Capability inventory: The orchestration examples involve calling specialized skills such as 'qe-test-generator', 'qe-test-executor', and 'qe-regression-risk-analyzer' using 'Task' and 'FleetManager' abstractions.\n- Sanitization: The documentation does not specify sanitization or validation logic for the ingested variables before they are processed by the agent fleet.
Audit Metadata