qa-testing-strategy

Warn

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONREMOTE_CODE_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [DYNAMIC_EXECUTION]: The script scripts/property_contract_runner.py implements a dynamic loading mechanism to execute Python code from external "adapter" files. It uses importlib.util.spec_from_file_location and spec.loader.exec_module(module) to load and run code specified via the --contract command-line argument. The skill's documentation explicitly notes that the runner imports and executes the Python file without sandboxing, which could be exploited if an agent is directed to run an untrusted or malicious contract file.
  • [REMOTE_CODE_EXECUTION]: The documentation in references/chaos-resilience-testing.md provides instructions to install third-party CLI tools using a piped remote script execution pattern: curl -L https://raw.githubusercontent.com/kubeshop/tracetest/main/install-cli.sh | bash. While targeting a known open-source project, this pattern is inherently risky as it executes remote content directly in the shell without prior verification.
  • [EXTERNAL_DOWNLOADS]: The skill recommends downloading and applying infrastructure configurations directly from remote sources, such as kubectl apply -f https://litmuschaos.github.io/litmus/litmus-operator-v3.0.0.yaml. Although these target established open-source services, they involve executing remote YAML configurations that control cluster-level resources.
  • [PRIVILEGE_ESCALATION]: The references/compliance-testing.md file suggests the use of sudo gor for traffic capture. Instructions that encourage the use of sudo for third-party utilities increase the risk of privilege abuse if the utility contains vulnerabilities or if the command is modified by a malicious actor.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process various forms of untrusted external data, including OpenAPI/AsyncAPI schemas, test results (JUnit XML), and security scan reports (Category 8).
  • Ingestion points: Untrusted data enters the agent context through data/sources.json and external files processed by the templates in assets/ and the logic in scripts/property_contract_runner.py.
  • Boundary markers: The skill lacks explicit instructions or delimiters to ignore embedded instructions within processed data.
  • Capability inventory: The skill possesses capabilities for subprocess execution (scripts/test_property_contract_runner.py), dynamic module execution (scripts/property_contract_runner.py), and file system operations.
  • Sanitization: There is no evidence of sanitization or validation of the content of processed schemas or test reports before they are used to influence the agent's testing strategy recommendations.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 23, 2026, 06:07 PM
Security Audit — agent-trust-hub — qa-testing-strategy