plan-tests
Pass
Audited by Gen Agent Trust Hub on Apr 8, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill consists entirely of instructional prompts and does not ship with any executable code, scripts, or binaries. It does not perform network operations or access sensitive system credentials.
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it ingests untrusted data from documentation files and external reports while possessing write capabilities to local files. \n- Ingestion points:
docs/playwright-spec-testing/test-plan.md,docs/playwright-spec-testing/project-context.md, and placeholders for pasting reviewer feedback/subagent reports. \n- Boundary markers: Absent; the prompts do not use specific delimiters or instructions to ignore embedded commands in the ingested data. \n- Capability inventory: The skill is capable of reading and writing to local markdown documentation files. \n- Sanitization: Absent; the ingested content is used directly to derive file paths and update status checkboxes.
Audit Metadata