qa-testing-strategy
Warn
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONREMOTE_CODE_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [DYNAMIC_EXECUTION]: The script
scripts/property_contract_runner.pyimplements a dynamic loading mechanism to execute Python code from external "adapter" files. It usesimportlib.util.spec_from_file_locationandspec.loader.exec_module(module)to load and run code specified via the--contractcommand-line argument. The skill's documentation explicitly notes that the runner imports and executes the Python file without sandboxing, which could be exploited if an agent is directed to run an untrusted or malicious contract file. - [REMOTE_CODE_EXECUTION]: The documentation in
references/chaos-resilience-testing.mdprovides instructions to install third-party CLI tools using a piped remote script execution pattern:curl -L https://raw.githubusercontent.com/kubeshop/tracetest/main/install-cli.sh | bash. While targeting a known open-source project, this pattern is inherently risky as it executes remote content directly in the shell without prior verification. - [EXTERNAL_DOWNLOADS]: The skill recommends downloading and applying infrastructure configurations directly from remote sources, such as
kubectl apply -f https://litmuschaos.github.io/litmus/litmus-operator-v3.0.0.yaml. Although these target established open-source services, they involve executing remote YAML configurations that control cluster-level resources. - [PRIVILEGE_ESCALATION]: The
references/compliance-testing.mdfile suggests the use ofsudo gorfor traffic capture. Instructions that encourage the use ofsudofor third-party utilities increase the risk of privilege abuse if the utility contains vulnerabilities or if the command is modified by a malicious actor. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process various forms of untrusted external data, including OpenAPI/AsyncAPI schemas, test results (JUnit XML), and security scan reports (Category 8).
- Ingestion points: Untrusted data enters the agent context through
data/sources.jsonand external files processed by the templates inassets/and the logic inscripts/property_contract_runner.py. - Boundary markers: The skill lacks explicit instructions or delimiters to ignore embedded instructions within processed data.
- Capability inventory: The skill possesses capabilities for subprocess execution (
scripts/test_property_contract_runner.py), dynamic module execution (scripts/property_contract_runner.py), and file system operations. - Sanitization: There is no evidence of sanitization or validation of the content of processed schemas or test reports before they are used to influence the agent's testing strategy recommendations.
Audit Metadata