skills/testland/qa/api-chaos-runner/Gen Agent Trust Hub

api-chaos-runner

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references the official Toxiproxy repository and Docker image maintained by Shopify. These are well-known, industry-standard tools for network simulation and do not represent a security risk when used as documented.
  • [COMMAND_EXECUTION]: The provided configuration examples and shell scripts (scripts/chaos-matrix.sh) use toxiproxy-cli and npx newman to orchestrate test runs. These are legitimate developer tools used within the intended scope of the skill's chaos testing functionality.
  • [SAFE]: Example credentials found in docker-compose.test.yml (user:pass) are standard documentation placeholders and do not expose real secrets.
  • [SAFE]: The skill's logic for building a chaos matrix and reporting failures is transparent and focused solely on verifying network resilience as described in the metadata.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 10:51 AM
Security Audit — agent-trust-hub — api-chaos-runner