e2e-testing

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFE
Full Analysis
  • [Prompt Injection] (SAFE): No instructions found that attempt to override system behavior, bypass safety filters, or extract system prompts.
  • [Data Exposure & Exfiltration] (SAFE): Uses industry-standard placeholder credentials ('password123') and generic environment variable patterns for CI tokens. No access to sensitive local file paths detected.
  • [Unverifiable Dependencies & Remote Code Execution] (SAFE): References trusted, industry-standard packages from Microsoft and other established providers. No piped shell execution or dynamic remote loading from untrusted sources.
  • [Indirect Prompt Injection] (LOW): The skill is designed to interact with external web content, which serves as a potential untrusted data ingestion surface. 1. Ingestion points: Web content via page.goto(). 2. Boundary markers: Absent in examples. 3. Capability inventory: Bash, Write, Edit tools. 4. Sanitization: Absent in examples. This is a low-risk surface inherent to the tool's intended purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:36 PM