crap-analysis

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the installation of the ReportGenerator tool via the .NET CLI from official registries. This is a standard procedure for generating human-readable coverage reports.\n- [COMMAND_EXECUTION]: Executes standard development commands including dotnet test, dotnet tool restore, and reportgenerator. These operations are required for the stated purpose of analyzing code quality and test coverage.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes structured XML coverage data to identify risk hotspots.\n
  • Ingestion points: XML coverage files generated by the testing framework (e.g., coverage.opencover.xml) found in the TestResults directory.\n
  • Boundary markers: None identified, as the skill works with local structured data files.\n
  • Capability inventory: Includes file system cleanup (rm), test execution, report generation, and opening generated HTML reports in the system browser.\n
  • Sanitization: Relies on the standard parsing logic within the ReportGenerator tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 07:31 AM
Security Audit — agent-trust-hub — crap-analysis