k6-load-testing

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill utilizes the Bash tool to execute standard k6 commands for load testing. This usage is consistent with the skill's stated purpose and is limited to performance benchmarking operations.
  • [SAFE]: The skill promotes secure credential management by explicitly instructing users to read authentication tokens from environment variables (__ENV.TOKEN) rather than hardcoding them within test scripts.
  • [SAFE]: The skill processes local files such as summary.json and test-results.json to provide performance feedback, which constitutes a potential indirect prompt injection surface. This behavior is inherent to the skill's function as a test reporter.
  • Ingestion points: Reads summary.json, test-results.json, and local JavaScript scripts.
  • Boundary markers: None explicitly defined for isolating tool output from agent instructions.
  • Capability inventory: Accesses Bash for command execution and WebFetch for network requests.
  • Sanitization: No specific sanitization of JSON result data is mentioned before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 08:14 AM
Security Audit — agent-trust-hub — k6-load-testing