cucumber-skill

Fail

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: CRITICAL
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references standard dependency management tools such as Maven (mvn) and NPM (npx) to download well-known packages including @cucumber/cucumber and chai from official registries.
  • [DATA_EXPOSURE]: The skill provides instructions for connecting to the LambdaTest Selenium hub (hub.lambdatest.com). While an automated scanner flagged this URL, LambdaTest is a well-known technology service, and the connection is a standard feature for cloud-based automated testing. The skill correctly recommends managing credentials via environment variables (LT_USERNAME, LT_ACCESS_KEY) rather than hardcoding secrets.
  • [COMMAND_EXECUTION]: The skill documents the use of standard testing commands like mvn test and npx cucumber-js for running generated tests. These are routine operations for software development workflows.
Recommendations
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 6, 2026, 01:11 PM
Security Audit — agent-trust-hub — cucumber-skill