stably-cli

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests natural language prompts to drive test generation and verification, creating a potential surface for indirect instructions.
  • Ingestion points: User prompts passed as arguments to stably plan, stably create, and stably verify as described in SKILL.md.
  • Boundary markers: Absent; inputs are interpolated directly into shell command arguments.
  • Capability inventory: The skill possesses file writing/modification capabilities (stably plan, stably fix, stably create) and shell command execution (stably test) across all referenced files.
  • Sanitization: The skill instructions do not specify input validation or sanitization, relying on the external CLI tool's internal logic.
  • [EXTERNAL_DOWNLOADS]: Fetches the Stably CLI and associated Playwright reporter from the vendor's official distribution channels.
  • [DYNAMIC_EXECUTION]: Automatically generates test.fixme() skeletons and functional Playwright test scripts based on AI-driven analysis of the codebase and user requirements.
  • [COMMAND_EXECUTION]: Invokes shell commands to perform test execution, environment management, and project initialization tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 12:09 AM
Security Audit — agent-trust-hub — stably-cli