promote-handover-test
Pass
Audited by Gen Agent Trust Hub on Apr 5, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues detected. The skill performs standard file system and command-line operations related to software development and testing.\n- [COMMAND_EXECUTION]: Executes Playwright tests locally via
npx playwright test. This is restricted to the local environment and is consistent with the skill's purpose of verifying promoted tests.\n- [DATA_EXFILTRATION]: No evidence of network activity, external downloads, or data exfiltration. All operations are confined to local test directories.\n- [PROMPT_INJECTION]: The skill contains clear, technical instructions without any behavioral overrides, role-play injections, or safety guideline bypasses. The risk of indirect prompt injection was analyzed: Ingestion points: Reads local test spec files frome2e/tests/handover/. Boundary markers: None. Capability inventory: File read, write, move, and delete; shell execution vianpx. Sanitization: None. This surface is considered safe given the intended development environment and the nature of the automated test modification.
Audit Metadata