skills/posit-dev/skills/r-testthat/Gen Agent Trust Hub

r-testthat

Pass

Audited by Gen Agent Trust Hub on Oct 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines patterns for ingesting external data from fixture files and API responses. While this creates a potential attack surface for indirect prompt injection if the test data is sourced from untrusted third parties, the skill encourages isolation through mocking and the use of dedicated fixture directories, which aligns with secure testing practices.
  • [SAFE]: The instructions and code snippets provided are standard practices for R package development. The skill relies on well-known, reputable R packages such as testthat, devtools, and usethis, and correctly guides users toward using temporary file systems and environment-based secret management.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 6, 2026, 09:00 PM