qa-test-plan
Pass
Audited by Gen Agent Trust Hub on Apr 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious behaviors or high-risk patterns were identified. The skill logic is consistent with its stated purpose of automating test plan generation through standard file reading and writing operations.\n- [PROMPT_INJECTION]: The skill defines a surface for indirect prompt injection as it ingests untrusted data from requirements files without explicit validation or delimiters. Ingestion points: business-requirements.yaml and technical-requirements.yaml in SKILL.md. Boundary markers: None present. Capability inventory: Reading local requirement files and writing a YAML test plan. Sanitization: No sanitization or content validation is performed.
Audit Metadata