qa-lead-strategy-advisor

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes data from the local codebase and user inputs to generate strategic advice. This creates a surface for indirect prompt injection where malicious content in scanned files could influence the agent's behavior.
  • Ingestion points: Codebase data retrieved via 'scan-automation-project' and interactive user interview responses.
  • Boundary markers: There are no specific delimiters or protective instructions used when integrating external data into the prompt context.
  • Capability inventory: The skill writes to the local filesystem ('.testeiya/TESTING.md') and can trigger further execution through specialized skills like 'testing-workflow'.
  • Sanitization: No evidence of sanitization or filtering of external data was identified.
  • [COMMAND_EXECUTION]: The skill invokes platform-specific tools including 'scan-automation-project' and 'AskUserQuestion'. It also delegates execution tasks to other skills like 'testing-workflow'. These actions are expected for its role as a QA lead and do not constitute arbitrary or unauthorized command execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 06:37 PM
Security Audit — agent-trust-hub — qa-lead-strategy-advisor