mushi-integration

Pass

Audited by Gen Agent Trust Hub on Aug 7, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the mushi CLI tool (the vendor's own tool) to perform integration tests such as mushi test, mushi stories map, and mushi tdd. These are legitimate diagnostic commands for the Mushi platform.
  • [COMMAND_EXECUTION]: The skill executes SQL queries via an MCP tool (Supabase MCP) to verify test results in the reports, inventory_proposals, and qa_stories tables. This is a standard practice for verifying backend state during a smoke test.
  • [EXTERNAL_DOWNLOADS]: The skill interacts with the vendor's own services and user-provided application URLs (e.g., https://your-app.com) for crawling and testing purposes. These are necessary for the skill's stated purpose of end-to-end integration testing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 7, 2026, 01:39 PM
Security Audit — agent-trust-hub — mushi-integration