testing
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines a specification and testing workflow that requires the agent to read and process external Markdown files (specs and implementation artifacts) to verify behavior and compliance.
- Ingestion points: Instructions in
SKILL.mddirect the agent to discover and read spec files in the.nlpm-test/directory and referenced implementation artifacts (e.g.,agents/my-agent.md). - Boundary markers: The documentation does not specify the use of boundary markers, delimiters, or explicit "ignore embedded instructions" warnings when evaluating the content of these files.
- Capability inventory: The skill references the use of tools/commands
/nlpm:testand/nlpm:score(described inSKILL.md) to analyze and report on the content of external artifacts. - Sanitization: No sanitization, validation, or filtering of the artifact content is described in the testing process.
Audit Metadata