qa-agent-testing
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEPROMPT_INJECTIONOBFUSCATIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill provides a detailed taxonomy and catalog of prompt injection payloads in
references/prompt-injection-testing.md, including instruction overrides ('Ignore all previous instructions'), role hijacking, and DAN-style jailbreaks. These are documented solely as test cases for robustness evaluation. - [OBFUSCATION]: Techniques such as Base64 encoding, zero-width characters, and homoglyph substitution are documented in
references/prompt-injection-testing.mdto demonstrate how attackers might attempt to smuggle tokens through filters. These examples are for educational and testing purposes. - [EXTERNAL_DOWNLOADS]: The documentation references and provides installation commands for several well-known and trusted evaluation platforms, including
deepeval,inspect-ai(UK AISI),promptfoo,ragas,braintrust,langfuse,garak(NVIDIA), andPyRIT(Microsoft). These tools are industry standards for LLM security and evaluation. - [INDIRECT_PROMPT_INJECTION]: The skill identifies potential attack surfaces for indirect prompt injection, including malicious tool outputs and poisoned RAG context, and provides testing strategies to mitigate these risks in
references/prompt-injection-testing.mdandreferences/tool-sandboxing.md. - [DYNAMIC_EXECUTION]: The skill includes a Python script
scripts/score_suite.pyfor computing evaluation metrics. The script performs mathematical calculations on input scores and does not contain dangerous dynamic execution patterns.
Audit Metadata