proof-api
Pass
Audited by Gen Agent Trust Hub on Jul 1, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues detected during the analysis of the skill instructions and metadata.
- [COMMAND_EXECUTION]: The skill uses the
Bashtool to perform environment detection and execute test runners (such as k6, Locust, or pytest). This is an expected capability for an API testing engineer persona and is used according to standard development practices. - [DATA_EXPOSURE]: While the skill maps API surfaces and identifies authentication requirements (e.g., JWT), it does so for the purpose of generating test suites. There is no evidence of credential harvesting or sensitive file exfiltration.
- [EXTERNAL_DOWNLOADS]: The instructions reference well-known, industry-standard testing frameworks and tools. No suspicious or unverified remote script execution patterns were identified.
Audit Metadata