pytest-advanced
Pass
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill presents a vulnerability surface for indirect prompt injection where malicious instructions could be ingested from the workspace.
- Ingestion points: The skill is configured to use
Read,Glob, andGreptools to read content from the local environment (SKILL.md). - Boundary markers: The skill does not provide any delimiters, boundary markers, or specific instructions to ignore embedded commands when processing external file content.
- Capability inventory: The skill has access to high-privilege tools including
Bashfor shell execution andWrite/Editfor file system modifications. - Sanitization: No sanitization, validation, or escaping logic is defined for data read from the environment before it is passed to execution tools.
- [METADATA_POISONING]: The skill content is misleading and inconsistent with its stated technical purpose.
- Although the skill is titled 'pytest-advanced' and describes Python testing concepts, the code examples provided are written in JavaScript syntax while being explicitly labeled as Python in the markdown blocks.
- The documentation is largely composed of generic placeholders and high-level boilerplate descriptions (e.g., 'Feature 1', 'Common Issue 1') rather than functional Pytest configurations, which could lead to agent confusion or incorrect tool usage.
Audit Metadata