shift-right-testing

Warn

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: MEDIUMPROMPT_INJECTION
Full Analysis
  • [Indirect Prompt Injection] (MEDIUM): The skill describes a pattern where agents ingest production data to drive automated code generation activities.- Ingestion points: Production incident data (e.g., INC-2024-001) and production logs are ingested via the Incident Replay task in SKILL.md.- Boundary markers: No explicit delimiters or instructions to ignore embedded malicious content are present in the pseudo-code for processing incident data.- Capability inventory: The qe-production-intelligence agent is granted capabilities to generateTests and addToRegression (file-write/code-generation) based on the processed external data.- Sanitization: There is no evidence of data sanitization or validation to prevent attacker-controlled incident metadata from being interpolated into the generated test code.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 17, 2026, 08:07 AM