spy-setup-helper

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: LOWNO_CODE
Full Analysis
  • [Prompt Injection] (SAFE): No instructions to override behavior or bypass safety guidelines were detected in the text.
  • [Data Exposure & Exfiltration] (SAFE): No hardcoded credentials, sensitive file paths, or network exfiltration patterns were identified.
  • [Unverifiable Dependencies & Remote Code Execution] (SAFE): The skill does not reference any external packages or perform remote code downloads.
  • [Indirect Prompt Injection] (LOW): The skill defines a surface for processing user-provided testing patterns and requests high-privilege tool access (Bash, Write). However, it contains no operational logic or scripts, meaning the capability cannot be exploited in its current state.
  • [Metadata Poisoning] (SAFE): Metadata fields are descriptive and consistent with the stated purpose of assisting with mocking (spies) in test automation.
Audit Metadata
Risk Level
LOW
Analyzed
Feb 17, 2026, 12:04 AM