llm-tester
Pass
Audited by Gen Agent Trust Hub on Jul 22, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references the use of
promptfoo, a widely recognized utility for testing LLM outputs. It is invoked using standard package management commands (npx promptfoo). - [COMMAND_EXECUTION]: Local shell commands are provided to facilitate environment grounding, such as inspecting configuration files and searching for test assets within the workspace. These commands are limited to legitimate project maintenance.
- [REMOTE_CODE_EXECUTION]: The skill describes using JavaScript and Python assertions for custom programmatic validation of model responses. This is a standard feature of the evaluation framework used to ensure output quality.
- [DATA_EXFILTRATION]: Mentions of API keys are restricted to GitHub Actions secret templates, which is the industry standard for secure credential management in automated workflows. No patterns of unauthorized data transmission were found.
Audit Metadata