skills/testland/qa/cucumber-testing/Gen Agent Trust Hub

cucumber-testing

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a comprehensive guide and evaluation set for Cucumber (BDD) testing.
  • [COMMAND_EXECUTION]: The skill includes standard build and test commands (e.g., mvn test, npx cucumber-js, gem install cucumber) which are expected and necessary for its primary purpose of configuring test runners. All commands target well-known package managers and official testing frameworks.
  • [EXTERNAL_DOWNLOADS]: The skill references official Cucumber documentation (cucumber.io) and legitimate package registries (NPM, Maven Central, RubyGems). These references are informational and consistent with the [TRUST-SCOPE-RULE] for well-known services.
  • [DATA_EXPOSURE_&_EXFILTRATION]: No sensitive file access or network exfiltration patterns were detected. Evaluation files use mocked 'seed-token' values for testing authentication flows in a safe, local-only context.
  • [INDIRECT_PROMPT_INJECTION]: The skill contains Gherkin feature files which are processed by the test runner. While these represent an ingestion surface for natural language instructions, the scope is limited to local testing environments and standard BDD practices, posing no risk to the agent's core safety guardrails (Severity: LOW).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 10:52 AM
Security Audit — agent-trust-hub — cucumber-testing