api-tester

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill does not contain instructions that attempt to override system behavior, bypass safety guardrails, or extract system prompts. It uses standard instructional language appropriate for its stated purpose.
  • [DATA_EXFILTRATION]: No patterns of sensitive data access or external exfiltration were found. The skill specifically mandates the use of deterministic test data (fixtures) and prohibits the use of production data, which reduces the risk of accidental sensitive data exposure.
  • [REMOTE_CODE_EXECUTION]: While the skill mentions tools like k6, Artillery, and Schemathesis, it does so within the context of generating test scripts and performing standard QA tasks. There are no instructions to download and execute untrusted code from remote sources.
  • [COMMAND_EXECUTION]: The skill describes behaviors for interacting with testing CLI tools, but does not provide malicious or excessive command sequences. It emphasizes reproducibility and environment-specific configuration via variables rather than hardcoding.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 05:15 PM
Security Audit — agent-trust-hub — api-tester