cypress-debugger
Warn
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The
publish-mochawesome-report.pyscript utilizesexec()andcompile()to dynamically load and execute the contents of a sibling script,read-cypress-artifact.py. While the script implements checks to ensure the file is a regular sibling within the trusted script directory, the use ofexec()on strings remains a high-risk dynamic execution pattern. - [DYNAMIC_EXECUTION]: The
download-cypress-reports.pyscript employsctypes.CDLL(None)to access platform-specific C libraries for atomic file publication (usingrenameat2on Linux andrenameatx_npon macOS). - [COMMAND_EXECUTION]: The skill facilitates the execution of project-local binaries, including
node_modules/.bin/cypressandnode_modules/.bin/mochawesome-merge. The skill's instructions mandate that the agent must not execute these until the user has explicitly trusted the repository and approved the exact command line and environment variables, mitigating the risk of executing malicious code hidden in the target project. - [EXTERNAL_DOWNLOADS]: The
download-cypress-reports.pyscript downloads test reports from GitHub Actions using the GitHub CLI (gh). The operation targets a well-known service (github.com) and includes validation logic to ensure the repository slug is valid and that the artifacts do not originate from forked pull request runs. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted data from Cypress test artifacts (mochawesome/JUnit reports, screenshots, and videos), which could contain malicious content such as reflected XSS payloads.
- Ingestion points: Content is read from
cypress/reports/,cypress/screenshots/, andcypress/videos/through theread-cypress-artifact.pyandextract-junit-failures.pyutilities. - Boundary markers: The
SKILL.mdincludes strict instructions to treat all report strings as untrusted data, render them as quoted text, and never follow instructions embedded within test titles or error messages. - Capability inventory: The skill has the capability to execute shell commands (via
subprocess.Popen), write to the filesystem, and perform network downloads viagh. - Sanitization: The skill includes
redact_artifact.pyandresidual_credentials.py, which implement sophisticated redaction logic using a 'marker invariant' to ensure sensitive tokens (API keys, cookies, Authorization headers) are removed from strings before output.
Audit Metadata