coverage-gaps
Pass
Audited by Gen Agent Trust Hub on Jul 25, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill executes standard development commands including
npm run test:unitto generate coverage reports andgit logto calculate code churn. These operations are transparent, scoped to the current project, and use safe argument handling to prevent shell injection.\n- [DATA_EXPOSURE]: The skill reads local project files and Istanbul/Vitest coverage JSON reports (coverage-final.json). This data access is essential for its primary function and is restricted to the local filesystem without any external exfiltration or network requests.\n- [PROMPT_INJECTION]: While the skill ingests untrusted data in the form of project source code and coverage reports, it does not automatically execute instructions found within that data. The agent is instructed to manually review high-risk gaps, and the logic inrank-gaps.mjsis strictly numerical and structural, posing no prompt injection risk.
Audit Metadata