web-testing
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references several industry-standard tools and libraries for installation and use, including Playwright, Vitest, k6, Axe-core, Lighthouse, Snyk, and Dredd. These are well-known developer tools and their use is consistent with the skill's stated purpose of web testing.\n- [COMMAND_EXECUTION]: The skill documentation includes examples of command-line tools for testing, such as
npx,k6,sqlmap, anddocker. These are presented as standard workflows for developers and are not invoked automatically by the skill.\n- [REMOTE_CODE_EXECUTION]: The filereferences/vulnerability-payloads.mdprovides examples of remote code execution payloads, such as Command Injection and XSS. These are provided strictly as educational reference material for security testing and do not indicate malicious intent within the skill's own code.\n- [SAFE]: The skill contains various security test payloads and encoded strings (e.g., path traversal) which are intended for DAST (Dynamic Application Security Testing) and are standard in a security testing context.
Audit Metadata