k6-test-maintenance
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill interacts with the local system and Grafana Cloud using several CLI tools including
k6,gcx, andk6-manage. It performs validation viak6 inspectand executes smoke tests usingk6 runandk6 cloud run. It also manages authentication for cloud operations by retrieving session tokens through thegcxutility as part of the documented developer workflow. - [EXTERNAL_DOWNLOADS]: The skill references external JavaScript libraries from
https://jslib.k6.io(the official k6 utility library) and fetches updated best practices and API documentation fromhttps://grafana.com. - [PROMPT_INJECTION]: The skill is subject to indirect prompt injection because it ingests and processes external k6 scripts from cloud and local sources. This risk is addressed by the skill's mandatory 'verification matrix' and the requirement for explicit user confirmation before applying any changes that alter runtime behavior. The capability inventory includes file editing and cloud deployment tools, but execution is guarded by validation steps like
k6 inspectandvalidate_script.
Audit Metadata