mastra-smoke-test

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill accesses sensitive local credential files, specifically ~/.mastra/credentials.json, and project-level .env files. This is used to manage authentication tokens and API keys for the Mastra platform and LLM providers during smoke testing and deployment flows.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it ingests and processes data from external GitHub PRs (titles, bodies, and diffs) that could contain malicious instructions.
  • Ingestion points: Files references/alpha-versioning-pr.md, scripts/check-versioning-pr.sh, and scripts/discover-release-scope.sh use gh pr view, gh pr list, and gh pr diff to retrieve external content.
  • Boundary markers: None identified in the processing scripts.
  • Capability inventory: The skill has capabilities for file system operations (pnpm create), deployment actions (pnpx mastra deploy), network operations (curl), and process management (kill).
  • Sanitization: Content is processed via jq and python3 regex for structured extraction.
  • [DYNAMIC_EXECUTION]: The skill builds and executes local 'experiment workers' by dynamically reading launch commands and arguments from a generated manifest file (experiment-worker-manifest.json) in references/tests/experiments.md.
  • [COMMAND_EXECUTION]: The skill makes extensive use of system utilities including the gh CLI, pnpm, npm, curl, lsof, and kill to orchestrate testing, clean up processes, and interact with vendor platform services.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 06:43 AM
Security Audit — agent-trust-hub — mastra-smoke-test