qa-agent-testing

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEPROMPT_INJECTIONOBFUSCATIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill provides a detailed taxonomy and catalog of prompt injection payloads in references/prompt-injection-testing.md, including instruction overrides ('Ignore all previous instructions'), role hijacking, and DAN-style jailbreaks. These are documented solely as test cases for robustness evaluation.
  • [OBFUSCATION]: Techniques such as Base64 encoding, zero-width characters, and homoglyph substitution are documented in references/prompt-injection-testing.md to demonstrate how attackers might attempt to smuggle tokens through filters. These examples are for educational and testing purposes.
  • [EXTERNAL_DOWNLOADS]: The documentation references and provides installation commands for several well-known and trusted evaluation platforms, including deepeval, inspect-ai (UK AISI), promptfoo, ragas, braintrust, langfuse, garak (NVIDIA), and PyRIT (Microsoft). These tools are industry standards for LLM security and evaluation.
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies potential attack surfaces for indirect prompt injection, including malicious tool outputs and poisoned RAG context, and provides testing strategies to mitigate these risks in references/prompt-injection-testing.md and references/tool-sandboxing.md.
  • [DYNAMIC_EXECUTION]: The skill includes a Python script scripts/score_suite.py for computing evaluation metrics. The script performs mathematical calculations on input scores and does not contain dangerous dynamic execution patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:07 PM
Security Audit — agent-trust-hub — qa-agent-testing