qa-lead-strategy-advisor
Pass
Audited by Gen Agent Trust Hub on Jul 10, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes data from the local codebase and user inputs to generate strategic advice. This creates a surface for indirect prompt injection where malicious content in scanned files could influence the agent's behavior.
- Ingestion points: Codebase data retrieved via 'scan-automation-project' and interactive user interview responses.
- Boundary markers: There are no specific delimiters or protective instructions used when integrating external data into the prompt context.
- Capability inventory: The skill writes to the local filesystem ('.testeiya/TESTING.md') and can trigger further execution through specialized skills like 'testing-workflow'.
- Sanitization: No evidence of sanitization or filtering of external data was identified.
- [COMMAND_EXECUTION]: The skill invokes platform-specific tools including 'scan-automation-project' and 'AskUserQuestion'. It also delegates execution tasks to other skills like 'testing-workflow'. These actions are expected for its role as a QA lead and do not constitute arbitrary or unauthorized command execution.
Audit Metadata