frontend-testing

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists of documentation, workflow guides, and reference material for frontend testing using industry-standard tools like Vitest and Playwright.
  • [SAFE]: Includes explicit security guidance for CI/CD workflows, recommending the pinning of GitHub Actions to specific commit SHAs and the implementation of least-privilege permissions for the GITHUB_TOKEN.
  • [SAFE]: All external tools and packages mentioned, such as @axe-core/playwright, are well-known, established utilities for their stated purposes.
  • [SAFE]: The skill identifies ingestion points for external data (e.g., ticket descriptions and Figma annotations) to define test criteria. While this constitutes an indirect prompt injection surface, it is central to the skill's primary purpose and no malicious exploitation patterns were detected.
  • Ingestion points: SKILL.md (Step 1: identification of requirements from tickets and Figma).
  • Boundary markers: None explicitly defined for isolating external requirements.
  • Capability inventory: Script generation and execution of tests via Vitest and Playwright.
  • Sanitization: Not applicable as the skill provides instructional guidance rather than automated processing code.
  • [SAFE]: No obfuscation, data exfiltration mechanisms, or persistence techniques were found.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 07:27 PM
Security Audit — agent-trust-hub — frontend-testing