pytest-skill
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the generation of test suites based on user-provided application code, representing an indirect injection surface. \n
- Ingestion points: User-provided source code and testing requirements processed by the agent (SKILL.md). \n
- Boundary markers: Absent; the skill templates do not define explicit delimiters for untrusted input. \n
- Capability inventory: None; the skill is documentation-only and does not contain executable scripts (.py, .js, .sh) or tool-execution logic. \n
- Sanitization: Absent; no input filtering or escaping is specified. \n- [SAFE]: The skill consists of instructional content and configuration templates (pytest.ini, pyproject.toml) following standard industry practices. No signs of obfuscation, exfiltration, or persistence were detected.
Audit Metadata