NYC

test-generator

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION] (LOW): The skill presents an indirect prompt injection surface because it processes untrusted source code and project configuration files to generate test output. \n- Ingestion points: Reads project source code and metadata files like package.json and requirements.txt. \n- Boundary markers: No explicit delimiters or instructions are provided to separate the ingested code from the tool's logic. \n- Capability inventory: The skill is granted 'Read', 'Write', and 'Edit' permissions, allowing it to modify the project filesystem. \n- Sanitization: No sanitization or validation of the analyzed source code is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 04:33 PM