qa-test-expert
Pass
Audited by Gen Agent Trust Hub on Mar 19, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface. Ingestion points: PRD documents and architectural designs (SKILL.md). Boundary markers: Absent. Capability inventory: Executes pytest, locust, ruff, and mypy (SKILL.md). Sanitization: Absent. This surface could allow maliciously crafted external documents to influence agent behavior during test generation or execution.
- [COMMAND_EXECUTION]: The skill utilizes command-line tools for testing and linting, including pytest, locust, ruff, and mypy. These executions are aligned with the skill's stated purpose of quality assurance and system stability validation.
Audit Metadata