test-it

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions focus on standard engineering practices (DORA, Google SRE, OWASP LLM) for verifying code quality. It includes explicit security-conscious instructions such as 'Redact secrets in fixtures and snapshots' and testing for 'jailbreak/injection' in generative AI components.
  • [COMMAND_EXECUTION]: The skill facilitates the execution of local testing harnesses (e.g., pytest, cargo test, npm test). This is the primary intended purpose of the skill and is performed within the context of a developer's repository. No unauthorized or suspicious network-based command execution was found.
  • [DATA_EXFILTRATION]: While the skill mentions using observability and evaluation tools like Langfuse or OpenTelemetry, these are standard industry practices for tracking AI experiment scores and do not represent unauthorized data exfiltration. The skill specifically warns against including sensitive data in shared test artifacts.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 09:44 PM
Security Audit — agent-trust-hub — test-it