k6-test-maintenance

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill interacts with the local system and Grafana Cloud using several CLI tools including k6, gcx, and k6-manage. It performs validation via k6 inspect and executes smoke tests using k6 run and k6 cloud run. It also manages authentication for cloud operations by retrieving session tokens through the gcx utility as part of the documented developer workflow.
  • [EXTERNAL_DOWNLOADS]: The skill references external JavaScript libraries from https://jslib.k6.io (the official k6 utility library) and fetches updated best practices and API documentation from https://grafana.com.
  • [PROMPT_INJECTION]: The skill is subject to indirect prompt injection because it ingests and processes external k6 scripts from cloud and local sources. This risk is addressed by the skill's mandatory 'verification matrix' and the requirement for explicit user confirmation before applying any changes that alter runtime behavior. The capability inventory includes file editing and cloud deployment tools, but execution is guarded by validation steps like k6 inspect and validate_script.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 07:02 AM
Security Audit — agent-trust-hub — k6-test-maintenance