allure-configure-reporting

Pass

Audited by Gen Agent Trust Hub on Jun 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for modifying build configuration files (e.g., package.json, pom.xml, build.gradle) and adding custom scripts to execute test runners and Allure CLI tools as part of its primary reporting configuration purpose.\n- [EXTERNAL_DOWNLOADS]: The skill directs the agent to consult official documentation at allurereport.org to verify package names and configuration syntax. This is a well-known service associated with the tool vendor.\n- [DATA_EXFILTRATION]: The skill guides the agent in configuring CI systems to upload Allure results as artifacts. This behavior is the intended primary purpose of the skill to enable persistent reporting and does not target sensitive user data.\n- [PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by configuring the environment to ingest and process allure-results data from external test runners.\n
  • Ingestion points: allure-results directory (SKILL.md, references/concepts.md)\n
  • Boundary markers: None\n
  • Capability inventory: File-write to configuration files and command execution for tests/reporting (SKILL.md, references/test-frameworks.md)\n
  • Sanitization: None
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 30, 2026, 01:56 PM
Security Audit — agent-trust-hub — allure-configure-reporting