skills/yeluyang/skills/testing/Gen Agent Trust Hub

testing

Pass

Audited by Gen Agent Trust Hub on Apr 10, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface. It analyzes the user's codebase (untrusted data) and uses this information to drive subsequent actions including file writing and command execution. * Ingestion points: step-1-code-analysis.md (reading function bodies) and step-3-existing-audit.md (reading existing test files). * Boundary markers: Absent; instructions do not specify delimiters for isolating code content. * Capability inventory: The skill can write files (step-4-spec-output.md, step-5-plan-and-execute.md) and execute shell commands (step-5-plan-and-execute.md, step-6-verification-loop.md). * Sanitization: Absent; the skill processes raw code content without filtering or escaping.
  • [COMMAND_EXECUTION]: The skill executes shell commands to run test runners and verify coverage, which is a core part of its workflow as seen in step-5-plan-and-execute.md and step-6-verification-loop.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 10, 2026, 02:44 AM
Security Audit — agent-trust-hub — testing