dev-testing
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFE
Full Analysis
- Security Invariant Verification: The skill defines a mandatory proof matrix for security-relevant features, requiring tests to actively attempt to bypass policy invariants, path traversal, and permission models. It outlines specific invariants to verify, such as directory isolation, socket permissions, and environment clearing.\n- Dependency Management and Auditing: The instructions mandate pinned versions for release-only generators and include blocking audits for RustSec and JavaScript advisories in the development and CI gates. This ensures that the build chain remains verifiable and secure.\n- Platform-Specific Security Controls: The skill includes platform gating tests to verify that sensitive platform APIs (e.g., Apple VZ, KVM) are correctly isolated behind target-specific conditional compilation. This prevents unintended leakage of platform-specific code.\n- Environment Isolation and Parity: It establishes strict local/CI parity rules, ensuring that all security-critical CI paths are executable locally. It utilizes containerization to mimic target environments, enabling accurate verification of permission-denied regressions and non-root execution paths.\n- Adversarial Testing Framework: The skill encourages an adversarial mindset, providing instructions on how to test for race conditions, malformed inputs, and sandbox escapes. This proactive approach helps identify and remediate potential security issues early in the development lifecycle.
Audit Metadata