email-testing

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill focuses on legitimate software testing methodologies using Playwright and standard email capture tools. The instructions follow security best practices such as avoiding hardcoded secrets and using deterministic addressing for parallel test isolation.
  • [CREDENTIALS_UNSAFE]: The skill explicitly advises against hardcoding API keys, instructing users to store credentials in environment variables or secrets (e.g., MAILOSAUR_API_KEY).
  • [EXTERNAL_DOWNLOADS]: References to external services are restricted to well-known and reputable technology providers including Mailosaur, MailSlurp, and Ethereal, as well as official Docker images for Mailpit. These are standard resources for the described use case.
  • [COMMAND_EXECUTION]: Examples provided involve standard Playwright automation and REST API interactions with local or hosted email services. These operations are within the expected scope of a QA/test engineering skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 08:31 AM
Security Audit — agent-trust-hub — email-testing