test-reviewer
Pass
Audited by Gen Agent Trust Hub on Apr 5, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local Python scripts (
trace_lint.pyandtrace_build_rtm.py) located within the vendor-owned directoryplugins/testany-eng/scripts/to validate test specifications. This is a primary function of the skill and uses local paths. - [SAFE]: The skill exhibits an indirect prompt injection surface as it ingests external project documentation. (Ingestion: Phase 0 reads PRD and Test Specs; Boundaries: Absent; Capability: Command execution in SKILL.md; Sanitization: Absent). This surface is consistent with the skill's purpose as a documentation reviewer and no malicious exploitation was observed.
Audit Metadata