k6-cloud-investigate-test

Pass

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the gcx (Grafana Cloud CLI) and jq utilities to perform API requests, verify connectivity, and format data. These tools are used within a documented 9-step workflow to fetch test metrics and logs.
  • [DATA_EXFILTRATION]: Network operations are restricted to the vendor's official infrastructure (Grafana Cloud) via the gcx tool. The data retrieved (logs, metrics, scripts) is necessary for the skill's diagnostic purpose.
  • [PROMPT_INJECTION]: An indirect prompt injection surface is present in Step 7, where the skill ingests and summarizes log lines from external test runs. While this poses a theoretical risk if logs contain adversarial content, the skill maintains a structured diagnostic context.
  • [COMMAND_EXECUTION]: Employs inline Python snippets for data manipulation, such as sorting and filtering test run results by date. This is used for local data processing of API responses and does not involve executing untrusted remote code.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 4, 2026, 08:26 PM
Security Audit — agent-trust-hub — k6-cloud-investigate-test