Versioned security assessment

Report ID: SA-9A8FE525

7/1/2026, 3:35:25 AM

test-driven-development security assessment v2

Skill Security Certification Report

Audit History
Audit model: codex Historical report
Skill name
test-driven-development
Version
v2
Maintainer
ZhanlinCui
Coverage
2 Files scanned · 672 Lines analyzed
Policy version
Unavailable

Confirmed finding summary

No confirmed security findings

The completed audit recorded no confirmed security findings. This is not proof that the Skill has no side effects.

Installation context

Historical evidence

This report may not describe the currently installable artifact. Open the current Skill page for install guidance.

Open current Skill page

This report does not block or authorize the manifest or ZIP.

Static findings for Ruby backticks, weak cryptography, and reconnaissance are false positives from Markdown fences and test examples. No evidence found for prompt injection, credential access, network exfiltration, or malicious commands. Medium risk remains because the skill strongly instructs agents to delete code when TDD order is violated.

Report position

Historical report

Open audit history before using this report to install.

Audit attestation

Not attestable

The required immutable binding is incomplete.

Human verification

Not verified

No human verification is recorded for this report.

Coverage

2 Files scanned · 672 Lines analyzed

2 items shown for review

Limitations

This report does not claim runtime or sandbox execution and does not prove the absence of side effects.

Evidence chain

Follow the evidence from source binding to the install contract. Available evidence supports verification; it is not a safety guarantee.

  1. Source

    Binding unavailable

  2. Artifact

    Identity incomplete

  3. Audit

    Complete

  4. Install contract

    Open manifest to verify

    Open manifest

Capabilities observed

Observed means this report recorded supporting evidence. Not recorded does not prove that a capability is absent.

Contains scripts

May execute code included with the Skill.

Not recorded by this audit

Network access

May connect to external services.

Not recorded by this audit

Filesystem access

May read or write local files.

Observed in 3 evidence locations

Env variables

May read values from the process environment.

Not recorded by this audit

External commands

May invoke commands or programs outside the Skill.

Observed in 4 evidence locations

Capability review items (2)
Medium
Potentially Destructive Workflow Guidance
The skill repeatedly instructs agents to delete code and start over when implementation precedes tests. This is not malicious, but it can cause user data loss if applied without confirmation.
The deletion guidance is explicit and repeated in the file. The impact depends on agent behavior and user confirmation controls, so confidence is high but not absolute.
Low
Local Test Command Execution
The skill tells agents to run local test commands such as npm test. This is expected for a coding skill, but project test scripts can execute arbitrary local commands.
The command examples are visible in Bash code blocks and are limited to local test execution. The risk is contextual because test scripts belong to the target project.

Risk findings

Confirmed security concerns are separated from items that still need review.

No confirmed security findings were recorded for this completed audit.

Expert evidence

Immutable subject identity, scanner metadata, dismissed matches, and source-level evidence.

Artifact subject

Marketplace commit
Unavailable
Content hash
Unavailable
Tree hash
Unavailable
Skill path
Unavailable
Audit payload hash
Unavailable

Analysis metadata

Audit model: codex

Analysis state: Complete

Scope is limited to the recorded files, lines, methods, and evidence. No runtime or sandbox execution is claimed.

Static false positives ignored (1)
Low
Static Analyzer False Positives
The reported Ruby backtick, weak cryptography, and reconnaissance hits do not show executable code or malicious intent. They are Markdown formatting and ordinary testing examples.
The reviewed locations are Markdown code fences or instructional snippets. No shell interpolation, crypto implementation, scanning command, or outbound endpoint was found.

Verify and export

The manifest and lockfile bind install artifacts to cryptographic hashes. This integrity claim is separate from the security assessment.

Audit attestation: not_attestable