llm-tester

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references the use of promptfoo, a widely recognized utility for testing LLM outputs. It is invoked using standard package management commands (npx promptfoo).
  • [COMMAND_EXECUTION]: Local shell commands are provided to facilitate environment grounding, such as inspecting configuration files and searching for test assets within the workspace. These commands are limited to legitimate project maintenance.
  • [REMOTE_CODE_EXECUTION]: The skill describes using JavaScript and Python assertions for custom programmatic validation of model responses. This is a standard feature of the evaluation framework used to ensure output quality.
  • [DATA_EXFILTRATION]: Mentions of API keys are restricted to GitHub Actions secret templates, which is the industry standard for secure credential management in automated workflows. No patterns of unauthorized data transmission were found.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 08:30 AM
Security Audit — agent-trust-hub — llm-tester