test-design-techniques

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external, untrusted data such as requirements, code, and API specifications to generate test cases, creating a potential surface for indirect prompt injection.
  • Ingestion points: Untrusted data enters the context through inputs defined in schemas/output.json (requirements, code, api-spec, user-story).
  • Boundary markers: No specific delimiters or "ignore instructions" markers are present to separate untrusted data from instructions.
  • Capability inventory: The skill coordinates multiple agents (qe-test-generator, qe-coverage-analyzer, qe-quality-analyzer) and generates test artifacts in various formats (JSON, YAML, Markdown, HTML, CSV).
  • Sanitization: No explicit validation or sanitization of input data is defined in the skill logic to prevent instruction leakage from untrusted input.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 06:21 PM
Security Audit — agent-trust-hub — test-design-techniques