e2e-test-generator

Pass

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill performs legitimate analysis of the Flutter project environment, reading files like pubspec.yaml and source code to generate appropriate test structures.
  • [EXTERNAL_DOWNLOADS]: Fetches test data from Notion using the Notion MCP. Notion is recognized as a well-known service.
  • [PROMPT_INJECTION]: The skill processes external Excel and Notion files, representing a surface for indirect prompt injection. Ingestion points: Excel (.xlsx) and Notion pages. Boundary markers: No explicit prompt delimiters for untrusted data. Capability inventory: File system read/write, shell command execution via bash, and Notion API access. Sanitization: No specific validation or escaping of external content mentioned. The risk is mitigated by the structural requirement for user confirmation at each phase of the generation process.
  • [COMMAND_EXECUTION]: Includes instructions for running Flutter tests and using developer tools like git and gh, which are appropriate for its function as a development aid.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 25, 2026, 06:05 PM
Security Audit — agent-trust-hub — e2e-test-generator