t3-testing-patterns
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [SAFE]: The skill implements a robust 'fail-closed' target validation system that uses short-lived capability files and cryptographically random tokens to authorize test runs and prevent unauthorized access to sensitive targets.
- [SAFE]: Extensive guidelines are provided for credential protection, including persona isolation using restricted file permissions (0700/0600) and mandatory sanitization of test artifacts to redact secrets, tokens, and sensitive headers before upload.
- [COMMAND_EXECUTION]: Defines standard root package commands (e.g.,
pnpm test:e2e,pnpm test:e2e:local) and usesdotenvxfor controlled environment variable loading during testing workflows. - [SAFE]: The included linting script (
lint-gates.mjs) and Playwright configuration template (playwright.config.sharding.ts) use standard Node.js APIs for filesystem access and validation without any detected network exfiltration, obfuscation, or dynamic code execution risks.
Audit Metadata