propagate
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest untrusted specifications and codebase data to automatically produce code, introducing a risk of indirect prompt injection.
- Ingestion points: Processes external
.alliumfiles, project files from the codebase, and JSON output data fromallium planandallium model(SKILL.md). - Boundary markers: Absent. The instructions do not define strict boundary markers or instructions to isolate the parsed specifications from the system prompt execution flow.
- Capability inventory: Possesses the capability to generate and write diverse test files, test fixtures, and scripts on the local file system for multiple ecosystems (TypeScript, Python, Rust, Go, Elixir).
- Sanitization: Absent. There are no mechanisms specified to filter, sanitize, or safely escape the external text contents prior to test generation.
Audit Metadata