pytest-fixtures
Pass
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to interact with and process external project files (test fixtures, conftest files) using tools like
Read,Glob, andGrep. This creates a surface for indirect prompt injection where malicious instructions embedded in codebase files could influence agent behavior. - Ingestion points: The agent utilizes
Read,Glob, andGrepto ingest content from the project's testing files (SKILL.md). - Boundary markers: The instructions do not define boundary markers or explicit warnings to the agent to disregard instructions found within the files it analyzes.
- Capability inventory: The skill allows the use of high-impact tools including
Bash,Write, andEdit, which could be exploited if the agent is compromised by injected content (SKILL.md). - Sanitization: There is no evidence of sanitization or filtering logic for the content read from external files.
- [METADATA_POISONING]: The skill contains significant inconsistencies between its stated purpose and the provided technical content. Although described as a Python Pytest skill, all code examples (Example 1 through 8) use JavaScript/TypeScript syntax (e.g.,
const,function,try/catch) instead of Python. This misleading content could lead to incorrect agent actions or misjudgment of the skill's utility. - [COMMAND_EXECUTION]: The skill's frontmatter allows the
Bashtool, and the documentation includes placeholders for installation commands. While no malicious shell payloads were found, the combination of shell access with the processing of untrusted local files contributes to the overall risk surface.
Audit Metadata