vitest
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The documentation provides instructions for installing standard development dependencies from the npm registry, such as
jsdom,happy-dom,@vitest/coverage-v8, and@vitest/coverage-istanbul. These are official packages associated with the Vitest ecosystem. - [COMMAND_EXECUTION]: The skill includes extensive documentation for the
vitestcommand-line interface, describing commands for running tests, generating coverage reports, and starting watch mode. These instructions are intended for user-initiated execution in a development environment. - [INDIRECT_PROMPT_INJECTION]: As a testing framework skill, the instructions guide the agent in processing and executing test suites. This involves an inherent risk if the agent is tasked with running tests on untrusted third-party code.
- Ingestion points: The skill is designed to handle user-provided source code and test files (e.g.,
**/*.test.ts). - Capability inventory: Vitest has the capability to write files (snapshots), spawn worker processes, and interact with the environment through configuration.
- Sanitization: The documentation focuses on standard usage; security depends on the execution environment's isolation (e.g., using the
threadsorvmThreadspools as described).
Audit Metadata