acceptance-test-from-criteria

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill follows established industry practices for Behavior-Driven Development (BDD) and Acceptance Test-Driven Development (ATDD). All identified patterns are consistent with its stated purpose of assisting in test scaffolding and documentation.
  • [COMMAND_EXECUTION]: The skill provides examples of standard shell commands for running tests using established frameworks such as Cucumber-JVM, Behave, and Reqnroll. These commands are informational and appropriate for the context.
  • [DYNAMIC_EXECUTION]: The skill demonstrates how to scaffold Python step definitions using NotImplementedError stubs. This is a common development practice intended for manual implementation by a developer and does not involve the AI agent executing arbitrary code at runtime.
  • [PROMPT_INJECTION]: No evidence of prompt injection, role-play bypasses, or instructions to ignore safety guidelines were found.
  • [DATA_EXFILTRATION]: The skill does not access sensitive local file paths (such as credentials or SSH keys) nor does it perform network operations to non-whitelisted or suspicious domains.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided acceptance criteria to generate tests. While this represents a data ingestion surface, the processing involves structural transformation into Gherkin syntax without executing the content, posing no significant security risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 10:50 AM
Security Audit — agent-trust-hub — acceptance-test-from-criteria