test-driven-development
Pass
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill uses strong, non-negotiable language such as "The Iron Law" and "Delete means delete" to enforce specific coding behaviors. While these are technically restrictive instructions, they are used to define the core TDD methodology rather than to bypass safety guardrails or override agent identity.- [COMMAND_EXECUTION]: Utilizes system commands like
pgrepandpkillto identify and terminate orphaned test runner processes (e.g., Vitest or Jest). This is a standard and expected administrative behavior within a development environment to ensure resource availability.- [PROMPT_INJECTION]: The skill's primary function involves reading and editing source code and test files, which presents a surface for indirect prompt injection from data in the workspace. This risk is inherent to development tools and is managed through the skill's narrow operational focus on passing specific test cases.
Audit Metadata