vitest-v4

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a technical reference for the Vitest 4 testing framework. It provides safe configuration templates and guidance for writing tests without introducing any unauthorized command execution or data exfiltration vectors.
  • [INDIRECT_PROMPT_INJECTION]: The skill assists with generating and running tests based on project source files. This creates a potential surface where an agent might process untrusted data found in test files, though this is inherent to its role as a developer tool.
  • Ingestion points: Test files (*.test.ts, *.browser.test.ts) and configuration files (vitest.config.ts, vite.config.ts) as referenced in SKILL.md and the references/ directory.
  • Boundary markers: Absent; the skill assumes the context of a developer working on their own codebase.
  • Capability inventory: Utilizes vitest run for code execution and npm install for dependency management, which are standard for the intended use-case.
  • Sanitization: None; it relies on the execution boundaries of the Vitest runner itself.
  • [EXTERNAL_DOWNLOADS]: All external URLs and package references target the official Vitest documentation domain (v4.vitest.dev) and official @vitest scoped packages on NPM. These are well-known, trusted resources within the JavaScript ecosystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 02:09 PM
Security Audit — agent-trust-hub — vitest-v4