coverage-gaps

Pass

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes standard development commands including npm run test:unit to generate coverage reports and git log to calculate code churn. These operations are transparent, scoped to the current project, and use safe argument handling to prevent shell injection.\n- [DATA_EXPOSURE]: The skill reads local project files and Istanbul/Vitest coverage JSON reports (coverage-final.json). This data access is essential for its primary function and is restricted to the local filesystem without any external exfiltration or network requests.\n- [PROMPT_INJECTION]: While the skill ingests untrusted data in the form of project source code and coverage reports, it does not automatically execute instructions found within that data. The agent is instructed to manually review high-risk gaps, and the logic in rank-gaps.mjs is strictly numerical and structural, posing no prompt injection risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 25, 2026, 04:27 AM
Security Audit — agent-trust-hub — coverage-gaps