test-generation

Pass

Audited by Gen Agent Trust Hub on Jul 6, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill involves analyzing external source code provided by users, which constitutes untrusted data. This introduces a surface for indirect prompt injection where instructions embedded in the code or comments could attempt to manipulate the agent's behavior.\n
  • Ingestion points: Processes user-supplied source code files and snippets in JavaScript, TypeScript, Python, Java, and other languages.\n
  • Boundary markers: The skill lacks explicit instructions or delimiters to ensure the agent ignores or isolates instructions contained within the input code.\n
  • Capability inventory: The agent generates executable test code, mock configurations, and coverage analyses based on the provided logic.\n
  • Sanitization: No sanitization, validation, or escaping of the input source code is specified in the instructions.\n- [NO_CODE]: The skill is composed solely of markdown instructions and does not contain any executable scripts, binaries, or complex configuration files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 6, 2026, 11:48 AM
Security Audit — agent-trust-hub — test-generation