tdd
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructions require the agent to execute shell commands to run and verify tests during the development cycle.
- Evidence: Found in
SKILL.md("Run the narrowest relevant test command", "Report the... exact commands run"). - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted external data (such as tickets, specifications, and architecture documents) and possesses command execution capabilities, creating a surface for indirect prompt injection.
- Ingestion points:
SKILL.mdrefers to reading authoritative tickets, specs, repository instructions, and domain/architecture documents. - Boundary markers: The skill includes logic to reject sources marked with
kind: "spec-explainer"and mandates resolving authoritative specs viaderived_fromfields. - Capability inventory: Shell command execution for running test suites.
- Sanitization: No explicit sanitization or escaping of external content before processing is mentioned, although it emphasizes limiting execution to "narrowest relevant test commands."
Audit Metadata