ultraqa
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill is designed to run various build and test commands (build, lint, typecheck, interactive) using the
omxCLI and system shell. - [DYNAMIC_EXECUTION]: The instructions mandate the generation and execution of temporary scripts, fixtures, and harnesses at runtime to facilitate end-to-end testing scenarios.
- [INDIRECT_PROMPT_INJECTION]: The skill has a high attack surface because its primary purpose is to ingest and process "hostile scenarios," including malformed input and prompt injection payloads, which are then used to build execution harnesses.
- Ingestion points: User-provided goals, custom patterns via the
--customflag, and project scope/acceptance criteria. - Boundary markers: The skill mentions "safety boundaries" and "safe substitutes" for unsafe scenarios but does not define specific technical delimiters (e.g., XML tags or unique markers) to isolate hostile payloads from the agent's core instructions.
- Capability inventory: File system writes, shell command execution (via
omx), script generation, and environment variable manipulation (env -u). - Sanitization: The skill recommends using a "safe file writer" with a "non-interpolating file-write mechanism" and avoiding interpolating heredocs for JavaScript assertions to prevent accidental code injection during harness creation.
Audit Metadata