manual-coverage

Pass

Audited by Gen Agent Trust Hub on May 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or unauthorized operations were detected. The skill adheres to the principle of least privilege by explicitly restricting modifications to non-source files and minimizing script execution to essential validation tasks.
  • [COMMAND_EXECUTION]: The skill uses shell commands like grep and npx to extract test identifiers and run reporting tools. These operations are scoped to identified test documentation and the produced configuration file, representing standard developer workflows.
  • [EXTERNAL_DOWNLOADS]: Dependencies are managed via npx and include standard utilities like js-yaml and official tools from the skill's author (@testomatio/reporter, check-tests). These resources are verified against the vendor's context and are necessary for the skill's primary function of integrating with the Testomat.io platform.
Audit Metadata
Risk Level
SAFE
Analyzed
May 20, 2026, 02:49 PM
Security Audit — agent-trust-hub — manual-coverage