cpp-testing

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses CMake's FetchContent to download GoogleTest from its official GitHub repository (github.com/google/googletest). This is a trusted source and a standard practice for C++ project dependency management.
  • [COMMAND_EXECUTION]: The skill provides standard build and test commands (cmake, ctest, lcov). These are legitimate development tools used within their intended scope for compiling, running, and analyzing test coverage.
  • [INDIRECT_PROMPT_INJECTION]: The skill includes sections on testing code that might process external data. However, it explicitly advocates for safe practices, such as using unique temporary directories and avoiding real network or filesystem dependencies in unit tests, which mitigates typical injection surfaces.
  • [DYNAMIC_EXECUTION]: The skill provides templates for runtime sanitizers (ASan, UBSan, TSan) and fuzzing (libFuzzer). These are standard security tools used to detect memory corruption and undefined behavior, rather than malicious dynamic code loading.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:39 PM
Security Audit — agent-trust-hub — cpp-testing