e2e-runner

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions define a structured development framework focusing on test-driven development (TDD), internal knowledge mapping, and deterministic execution. No malicious code, exfiltration patterns, or obfuscation were found.
  • [COMMAND_EXECUTION]: The document references an 'ExecutionProxy Interface' using a custom prefix (e.g., 'rtk npm test') for running tests and terminal actions. This is standard functionality for a developer-oriented agent skill.
  • [DATA_EXPOSURE]: References to 'docs/graph.json' and 'docs/departments/' are used for project-specific architectural discovery and knowledge management rather than harvesting sensitive system credentials or PII.
  • [INDIRECT_PROMPT_INJECTION]: The skill explicitly instructs the agent to treat external web content as hostile and to redact secrets before sharing context, which represents a security best practice for handling untrusted inputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 07:35 AM
Security Audit — agent-trust-hub — e2e-runner