ultraqa

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill is designed to run various build and test commands (build, lint, typecheck, interactive) using the omx CLI and system shell.
  • [DYNAMIC_EXECUTION]: The instructions mandate the generation and execution of temporary scripts, fixtures, and harnesses at runtime to facilitate end-to-end testing scenarios.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a high attack surface because its primary purpose is to ingest and process "hostile scenarios," including malformed input and prompt injection payloads, which are then used to build execution harnesses.
  • Ingestion points: User-provided goals, custom patterns via the --custom flag, and project scope/acceptance criteria.
  • Boundary markers: The skill mentions "safety boundaries" and "safe substitutes" for unsafe scenarios but does not define specific technical delimiters (e.g., XML tags or unique markers) to isolate hostile payloads from the agent's core instructions.
  • Capability inventory: File system writes, shell command execution (via omx), script generation, and environment variable manipulation (env -u).
  • Sanitization: The skill recommends using a "safe file writer" with a "non-interpolating file-write mechanism" and avoiding interpolating heredocs for JavaScript assertions to prevent accidental code injection during harness creation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 04:53 PM
Security Audit — agent-trust-hub — ultraqa