skills/shipshitdev/skills/tdd/Gen Agent Trust Hub

tdd

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data (feature requests, bug reports, PRDs) to generate code and verification tests, creating an attack surface for indirect instructions.
  • Ingestion points: Data enters the context via the 'Contract' inputs in SKILL.md, such as feature requests and bug reports.
  • Boundary markers: The skill enforces a strict 'Red-Green-Refactor' workflow which requires independent verification at each step, acting as a logical boundary. However, it does not define explicit data delimiters or instructions to ignore instructions embedded within the inputs.
  • Capability inventory: The skill has the capability to create or modify production and test files, and execute verification commands (identified in SKILL.md and references/tdd-procedure.md).
  • Sanitization: There are no explicit instructions to sanitize or escape input data before processing.
  • [COMMAND_EXECUTION]: The skill requires the agent to execute verification commands as a core part of its workflow.
  • Evidence: SKILL.md and references/tdd-procedure.md instruct the agent to identify and run the 'narrowest executable check' to verify behavior. The references/tdd-procedure.md file specifically notes that the agent should only use capabilities the active harness actually exposes.
  • [EXTERNAL_DOWNLOADS]: The skill's documentation and metadata reference external GitHub repositories for source attribution and synchronization.
  • Evidence: Links to anthropics/claude-plugins-official, cursor/plugins, mattpocock/skills, and ericlitman/open-pstack appear in README.md, SKILL.md, and licenses/NOTICE.txt.
  • Context: These are informational references for upstream tracking and do not involve direct runtime network operations or remote code execution commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 05:10 AM
Security Audit — agent-trust-hub — tdd