improve-test-suite
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to analyze untrusted repository data (source code and test suites). It lacks explicit boundary markers or instructions to the agent to disregard potential instructions embedded within the data it audits, creating a surface for indirect prompt injection.\n
- Ingestion points: Audited repository files and test suites accessed via file system tools.\n
- Boundary markers: No specific delimiters or "ignore" instructions are provided to separate data from the system prompt.\n
- Capability inventory: Reading repository files and writing a prioritized cleanup plan to a target file (SKILL.md, step 8).\n
- Sanitization: No explicit sanitization or validation of the ingested code content is described.
Audit Metadata