cypress-debugger

Warn

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The publish-mochawesome-report.py script utilizes exec() and compile() to dynamically load and execute the contents of a sibling script, read-cypress-artifact.py. While the script implements checks to ensure the file is a regular sibling within the trusted script directory, the use of exec() on strings remains a high-risk dynamic execution pattern.
  • [DYNAMIC_EXECUTION]: The download-cypress-reports.py script employs ctypes.CDLL(None) to access platform-specific C libraries for atomic file publication (using renameat2 on Linux and renameatx_np on macOS).
  • [COMMAND_EXECUTION]: The skill facilitates the execution of project-local binaries, including node_modules/.bin/cypress and node_modules/.bin/mochawesome-merge. The skill's instructions mandate that the agent must not execute these until the user has explicitly trusted the repository and approved the exact command line and environment variables, mitigating the risk of executing malicious code hidden in the target project.
  • [EXTERNAL_DOWNLOADS]: The download-cypress-reports.py script downloads test reports from GitHub Actions using the GitHub CLI (gh). The operation targets a well-known service (github.com) and includes validation logic to ensure the repository slug is valid and that the artifacts do not originate from forked pull request runs.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted data from Cypress test artifacts (mochawesome/JUnit reports, screenshots, and videos), which could contain malicious content such as reflected XSS payloads.
  • Ingestion points: Content is read from cypress/reports/, cypress/screenshots/, and cypress/videos/ through the read-cypress-artifact.py and extract-junit-failures.py utilities.
  • Boundary markers: The SKILL.md includes strict instructions to treat all report strings as untrusted data, render them as quoted text, and never follow instructions embedded within test titles or error messages.
  • Capability inventory: The skill has the capability to execute shell commands (via subprocess.Popen), write to the filesystem, and perform network downloads via gh.
  • Sanitization: The skill includes redact_artifact.py and residual_credentials.py, which implement sophisticated redaction logic using a 'marker invariant' to ensure sensitive tokens (API keys, cookies, Authorization headers) are removed from strings before output.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 21, 2026, 06:37 PM
Security Audit — agent-trust-hub — cypress-debugger