spec-test-execute
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns, obfuscation, or unauthorized network operations were detected. The skill's behavior matches its stated purpose of generating test reports.
- [DATA_EXPOSURE]: The skill reads local project context files such as product and technical memory to ensure report accuracy. This access is restricted to the local file system and is necessary for the reporting task.
- [PROMPT_INJECTION]: The skill processes content from project documentation which presents a surface for indirect prompt injection.
- Ingestion points: project/memory/product.md, project/memory/tech.md, project/memory/glossary.md, verification/test-plan.md, and verification/usecase.md.
- Boundary markers: Absent.
- Capability inventory: File reading and writing of Markdown reports to the project's verification directory.
- Sanitization: Absent.
Audit Metadata