k6-cloud-investigate-test
Pass
Audited by Gen Agent Trust Hub on Aug 4, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
gcx(Grafana Cloud CLI) andjqutilities to perform API requests, verify connectivity, and format data. These tools are used within a documented 9-step workflow to fetch test metrics and logs. - [DATA_EXFILTRATION]: Network operations are restricted to the vendor's official infrastructure (Grafana Cloud) via the
gcxtool. The data retrieved (logs, metrics, scripts) is necessary for the skill's diagnostic purpose. - [PROMPT_INJECTION]: An indirect prompt injection surface is present in Step 7, where the skill ingests and summarizes log lines from external test runs. While this poses a theoretical risk if logs contain adversarial content, the skill maintains a structured diagnostic context.
- [COMMAND_EXECUTION]: Employs inline Python snippets for data manipulation, such as sorting and filtering test run results by date. This is used for local data processing of API responses and does not involve executing untrusted remote code.
Audit Metadata