skills/midudev/autoskills/vitest/Gen Agent Trust Hub

vitest

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The documentation provides instructions for installing standard development dependencies from the npm registry, such as jsdom, happy-dom, @vitest/coverage-v8, and @vitest/coverage-istanbul. These are official packages associated with the Vitest ecosystem.
  • [COMMAND_EXECUTION]: The skill includes extensive documentation for the vitest command-line interface, describing commands for running tests, generating coverage reports, and starting watch mode. These instructions are intended for user-initiated execution in a development environment.
  • [INDIRECT_PROMPT_INJECTION]: As a testing framework skill, the instructions guide the agent in processing and executing test suites. This involves an inherent risk if the agent is tasked with running tests on untrusted third-party code.
  • Ingestion points: The skill is designed to handle user-provided source code and test files (e.g., **/*.test.ts).
  • Capability inventory: Vitest has the capability to write files (snapshots), spawn worker processes, and interact with the environment through configuration.
  • Sanitization: The documentation focuses on standard usage; security depends on the execution environment's isolation (e.g., using the threads or vmThreads pools as described).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 11:20 PM
Security Audit — agent-trust-hub — vitest