nestjs-e2e-practices

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill provides structured guidance for NestJS E2E testing. It includes explicit warnings against pointing destructive operations at shared or production resources and instructs the agent to avoid exposing credentials or secrets in its output.
  • [COMMAND_EXECUTION]: The skill directs the agent to execute project-defined testing commands (e.g., Jest, Prisma migrations). This behavior is aligned with the skill's primary purpose and relies on the project's existing, verified configuration.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from target project source code and test runner outputs. It possesses capabilities to execute commands and write files. However, it incorporates strong sanitization instructions, requiring the agent to assert the absence of secrets in responses and to maintain isolation between test and production environments. (Severity: SAFE).
  • [EXTERNAL_DOWNLOADS]: The skill references documentation from trusted and well-known services, including NestJS, Jest, MDN, and Prisma. These references are used for normative guidance and do not involve untrusted remote code execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 08:19 PM
Security Audit — agent-trust-hub — nestjs-e2e-practices