qa-write-test-cases

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a robust interaction model with mandatory approval gates at each workflow step, requiring user confirmation of the gathered context and generated checklists before creating test files.
  • [COMMAND_EXECUTION]: The skill leverages the testomatio MCP and specialized synchronization skills to interact with the Test Management System, which is appropriate for its stated purpose of QA automation management.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates downloading existing test cases from the Testomat.io platform to avoid duplication, representing standard integration behavior with the vendor's services.
  • [PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection due to its ingestion of external data from sources like Jira and Confluence. This risk is managed through explicit user review steps where the agent summarizes gathered information before proceeding.
  • [DATA_EXFILTRATION]: While the skill accesses project source code and test files, it limits its operations to reading for context and writing new test documentation to specific, often git-ignored, directories.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 06:37 PM
Security Audit — agent-trust-hub — qa-write-test-cases