e2e-runner
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill instructions define a structured development framework focusing on test-driven development (TDD), internal knowledge mapping, and deterministic execution. No malicious code, exfiltration patterns, or obfuscation were found.
- [COMMAND_EXECUTION]: The document references an 'ExecutionProxy Interface' using a custom prefix (e.g., 'rtk npm test') for running tests and terminal actions. This is standard functionality for a developer-oriented agent skill.
- [DATA_EXPOSURE]: References to 'docs/graph.json' and 'docs/departments/' are used for project-specific architectural discovery and knowledge management rather than harvesting sensitive system credentials or PII.
- [INDIRECT_PROMPT_INJECTION]: The skill explicitly instructs the agent to treat external web content as hostile and to redact secrets before sharing context, which represents a security best practice for handling untrusted inputs.
Audit Metadata