unit-tests

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill identifies and runs local test frameworks such as Jest or PHPUnit. This enables the agent to execute code within the repository to analyze test behavior and verify improvements.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection by processing external repository files. Malicious content within source code or tests could attempt to override the auditor's logic or force specific file changes.
  • Ingestion points: Code and test files matched via glob patterns during the discovery phase.
  • Boundary markers: Lacks specific delimiters or instructions to ignore instructions embedded in the ingested content.
  • Capability inventory: Includes filesystem write access and local shell command execution via test runners.
  • Sanitization: No sanitization or filtering of the processed file content is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 10:50 AM
Security Audit — agent-trust-hub — unit-tests