test-automator

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill provides an attack surface for indirect prompt injection through its ingestion of external data. \n- Ingestion points: The skill analyzes untrusted codebases and external research data from tools like exa search and context7 MCP to perform test automation tasks. \n- Boundary markers: There are no instructions to use delimiters or ignore embedded instructions within the processed data. \n- Capability inventory: The skill utilizes powerful tools including Bash, Write, and Edit, which could be exploited if malicious instructions are successfully injected into the agent's context. \n- Sanitization: The skill does not include any guidance on sanitizing or validating the contents of the files or research results it processes before they are interpreted.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 02:24 AM
Security Audit — agent-trust-hub — test-automator