testing-perf

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions involve processing source code to generate performance tests, creating an attack surface where instructions embedded in processed data could influence the agent.\n
  • Ingestion points: The agent is instructed to read local project files and test suites using tools like Read, Glob, and Grep (e.g., in rules/execution.md).\n
  • Boundary markers: No explicit boundary markers or instructions to ignore embedded commands are defined in the instructions for the data being processed.\n
  • Capability inventory: The agent has access to potentially sensitive capabilities including WebFetch and file system read tools.\n
  • Sanitization: The skill lacks explicit guidance on sanitizing or escaping content from ingested files before it is included in the agent's context or output.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 02:15 AM
Security Audit — agent-trust-hub — testing-perf