test-automator
Pass
Audited by Gen Agent Trust Hub on Aug 1, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill provides an attack surface for indirect prompt injection through its ingestion of external data. \n- Ingestion points: The skill analyzes untrusted codebases and external research data from tools like exa search and context7 MCP to perform test automation tasks. \n- Boundary markers: There are no instructions to use delimiters or ignore embedded instructions within the processed data. \n- Capability inventory: The skill utilizes powerful tools including Bash, Write, and Edit, which could be exploited if malicious instructions are successfully injected into the agent's context. \n- Sanitization: The skill does not include any guidance on sanitizing or validating the contents of the files or research results it processes before they are interpreted.
Audit Metadata