devassure

Pass

Audited by Gen Agent Trust Hub on Apr 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The DevAssure CLI allows users to define custom tools in .devassure/tools/index.yaml that execute shell commands via an exec field. This feature supports argument substitution and setup steps like npm install, which is intended for extending testing capabilities.- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the @devassure/cli package from the public NPM registry. It also specifies communication with several vendor-owned endpoints for authentication and processing, including app.devassure.io and a Heroku-hosted service (devassure-llm-2e2fa73b953b.herokuapp.com).- [DATA_EXFILTRATION]: The skill documents the management of authentication tokens for CI/CD environments and the storage of application credentials in test_data.yaml. While these involve sensitive data, the practices described follow standard configuration patterns for automated testing tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 24, 2026, 09:19 AM