test-automator
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The Python scripts
scripts/generate_test.pyandscripts/coverage_report.pyinterpolate user-supplied command-line arguments directly into generated Markdown templates without sanitization. - Ingestion points: Arguments such as
--nameand--ownerprovided to the scriptsscripts/generate_test.pyandscripts/coverage_report.py. - Boundary markers: None present in the template logic to delimit or neutralize user-supplied content.
- Capability inventory: The skill can perform file-write operations to the local file system using
pathlib.Path.write_textvia its included scripts. - Sanitization: There is no escaping or validation of input strings before they are interpolated and written to output files.
Audit Metadata