backend-test
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
bashto execute project-specific test runners (e.g.,npm test,pytest,go test). This is a core feature of the skill's intended purpose for backend testing automation. - [COMMAND_EXECUTION]: In
mode=auto, the skill is instructed to execute detected test commands immediately and report results without asking for confirmation. This behavior is triggered by specific user requests like 'run tests' and is scoped to the developer's local environment commands. - [DATA_EXPOSURE]: The skill reads project configuration files such as
package.json,pyproject.toml, andgo.modto identify the appropriate test runner and environment settings. This is standard behavior for professional development tools. - [INDIRECT_PROMPT_INJECTION]: The skill has a data ingestion surface where it reads project configuration files to determine which shell commands to run. While this represents a technical attack surface if a project file were maliciously modified, the skill operates within the expected capabilities of a developer assistant.
Audit Metadata