load-test

Warn

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill uses behavioral overrides ('AUTONOMOUS MODE', 'Do NOT ask questions') to suppress standard agent safety protocols and human-in-the-loop confirmation for resource-intensive operations.
  • [COMMAND_EXECUTION]: The skill executes shell commands to install third-party packages and run load-testing tools. It uses project discovery to drive command parameters, which may be influenced by untrusted project configuration files.
  • [REMOTE_CODE_EXECUTION]: The skill dynamically generates and executes JavaScript and Python scripts based on its discovery phase. It is vulnerable to indirect prompt injection because it ingests data from project files (package.json, requirements.txt, go.mod, Gemfile) without boundary markers or sanitization, while maintaining a capability inventory that includes shell execution and file-write operations.
  • [EXTERNAL_DOWNLOADS]: The skill initiates downloads and installations of software packages from public registries (NPM and PyPI) during its discovery and setup phase.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 23, 2026, 10:57 AM
Security Audit — agent-trust-hub — load-test