test-reviewer

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local Python scripts (trace_lint.py and trace_build_rtm.py) located within the vendor-owned directory plugins/testany-eng/scripts/ to validate test specifications. This is a primary function of the skill and uses local paths.
  • [SAFE]: The skill exhibits an indirect prompt injection surface as it ingests external project documentation. (Ingestion: Phase 0 reads PRD and Test Specs; Boundaries: Absent; Capability: Command execution in SKILL.md; Sanitization: Absent). This surface is consistent with the skill's purpose as a documentation reviewer and no malicious exploitation was observed.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 08:28 PM