tdd-workflows-tdd-red
Pass
Audited by Gen Agent Trust Hub on Jul 9, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious activities such as data exfiltration, persistence, or privilege escalation were detected. The skill correctly identifies its purpose and provides framework-specific patterns for Jest, pytest, Go, and RSpec.\n- [PROMPT_INJECTION]: The skill contains an indirect prompt injection surface by using the $ARGUMENTS placeholder to interpolate user input into the prompt. This is a common pattern for instructional skills.\n
- Ingestion points: $ARGUMENTS variable in the prompt template within SKILL.md.\n
- Boundary markers: None; user input is directly included in the final prompt string.\n
- Capability inventory: The skill uses the Task tool with a unit-testing::test-automator subagent, which involves code generation and execution capabilities.\n
- Sanitization: The skill does not perform any explicit sanitization or validation of the input arguments.
Audit Metadata