locust-best-practices
Pass
Audited by Gen Agent Trust Hub on Mar 29, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill promotes secure development practices by recommending the use of environment variables for sensitive data like passwords and API tokens, rather than hardcoding them in test scripts.
- [EXTERNAL_DOWNLOADS]: The skill mentions the installation of standard, well-known Python packages from public registries, specifically locust, websocket-client, and grpcio, which are essential for the skill's stated purpose.
- [COMMAND_EXECUTION]: The skill generates legitimate CLI commands for the locust tool to automate performance tests and generate reports, which is the primary intent of the extension.
- [SAFE]: All provided code examples and instructions are transparent, follow expected patterns for the Locust framework, and do not contain any obfuscation or unauthorized system access attempts.
Audit Metadata