ai-regression-testing
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted external data, such as bug reports and code diffs, which can serve as vectors for indirect prompt injection. If an attacker provides a malicious diff or bug report containing instructions designed to influence the agent's behavior during the test generation or execution phase, the agent might inadvertently execute unintended actions.
- Ingestion points: The skill accepts "Bug report, code diff, API change, route, component, feature flag, or sandbox path" as inputs in
SKILL.md. - Boundary markers: Absent. The instructions do not define clear delimiters or instruct the agent to ignore instructions that might be embedded within the provided code or bug reports.
- Capability inventory: The skill workflow in
SKILL.md(Section 5) involves executing shell commands such asbun testandbun run typecheckto verify the code. - Sanitization: Absent. There are no explicit steps to sanitize or validate the structure of the input data before it is used to generate or execute tests.
- [COMMAND_EXECUTION]: The skill workflow explicitly instructs the agent to execute shell commands to perform verification tasks.
- Evidence: The verification section in
SKILL.mdincludes commands such asbun test path/to/regression.test.ts,bun test, andbun run typecheck.
Audit Metadata