t3-testing-patterns

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill implements a robust 'fail-closed' target validation system that uses short-lived capability files and cryptographically random tokens to authorize test runs and prevent unauthorized access to sensitive targets.
  • [SAFE]: Extensive guidelines are provided for credential protection, including persona isolation using restricted file permissions (0700/0600) and mandatory sanitization of test artifacts to redact secrets, tokens, and sensitive headers before upload.
  • [COMMAND_EXECUTION]: Defines standard root package commands (e.g., pnpm test:e2e, pnpm test:e2e:local) and uses dotenvx for controlled environment variable loading during testing workflows.
  • [SAFE]: The included linting script (lint-gates.mjs) and Playwright configuration template (playwright.config.sharding.ts) use standard Node.js APIs for filesystem access and validation without any detected network exfiltration, obfuscation, or dynamic code execution risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 06:18 PM
Security Audit — agent-trust-hub — t3-testing-patterns