tdd
Pass
Audited by Gen Agent Trust Hub on May 12, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill uses a dynamic context injection pattern in
SKILL.md(!mkdir -p .claude && touch .claude/.tdd-active) to create a local state marker for the TDD workflow. This operation is benign, uses local paths, and does not perform network activity or access sensitive system credentials.- [SAFE]: The skill processes user-provided code and test results as part of the TDD cycle. This represents a standard surface for indirect prompt injection. Ingestion points: User source code and test output logs. Boundary markers: No explicit delimiters or instructions to ignore embedded commands are defined. Capability inventory: The skill assumes the agent can write source files and execute shell commands to run test suites. Sanitization: No specific filtering or validation of external code content is described in the workflow.
Audit Metadata