tdd
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists entirely of documentation and workflow instructions for software development. It contains no executable code, shell scripts, or automated triggers.
- [DATA_EXPOSURE]: The workflow suggests that the agent read a 'CONTEXT.md' file to understand project domain language. While this involves ingesting local project data, the skill does not include any mechanisms for data exfiltration or unauthorized network access.
- [PROMPT_INJECTION]: The instructions are standard software engineering principles and do not contain patterns intended to bypass AI safety filters or override system instructions.
- [CREDENTIALS_UNSAFE]: A code example in 'mocking.md' references 'STRIPE_KEY' via 'process.env', which follows secure development practices for secret management and does not contain hardcoded credentials.
Audit Metadata