Security risk report for @forgecat/contains-studio_agents_testing v0.1.2
Source Integrity
Low
Profile declares origin as Contains Studio (GitHub: contains-studio/agents), with commit hash and repository link provided.
No typosquatted, attacker-controlled, or suspicious package dependencies are recommended.
Static scanner confirms low risk; source attribution is transparent and verifiable.
Agent Intent
Low
Content describes legitimate testing, performance analysis, and workflow optimization practices without instructing the AI to ignore system instructions, read credentials, or exfiltrate data.
No prompt injection, system prompt leakage, or guidance poisoning detected; the agents are instructed to perform standard QA, benchmarking, and process improvement tasks.
Recommendations for tools (k6, Lighthouse, Pact, etc.) are well-known, legitimate open-source and commercial products—not typosquatted or backdoored alternatives.
performance-benchmarker.md: 'Profiling CPU usage and hot paths... Measuring page load times...' — legitimate optimization guidance.
test-results-analyzer.md: 'Parsing test execution logs... Identifying failure patterns...' — standard test analysis, no instruction to hide or leak data.
tool-evaluator.md: 'Create proof-of-concept implementations... Test core features...' — pragmatic tool assessment, no malicious guidance.
workflow-optimizer.md: 'Documenting current process steps... Identifying manual tasks...' — process improvement, no instruction to manipulate the AI or exfiltrate data.
Permissions
Low
Declared tools (Bash, Read, Write, Grep, WebFetch, MultiEdit, TodoWrite) are appropriate for the stated functions: testing, analysis, reporting, and documentation.
No high-risk categories (file_delete, shell with alwaysApply=true and globs='**') are present; Bash and file operations are scoped to legitimate testing and analysis workflows.
Tool authority matches the described responsibilities: reading test logs, writing reports, running performance tests, and fetching documentation.
Details
Evidence
api-tester.md tools: 'Bash, Read, Write, Grep, WebFetch, MultiEdit' — appropriate for load testing and API validation.
performance-benchmarker.md tools: 'Bash, Read, Write, Grep, MultiEdit, WebFetch' — suitable for profiling and benchmarking.
test-results-analyzer.md tools: 'Read, Write, Grep, Bash, MultiEdit, TodoWrite' — aligned with log parsing and report generation.
tool-evaluator.md tools: 'WebSearch, WebFetch, Write, Read, Bash' — reasonable for research and POC testing.
workflow-optimizer.md tools: 'Read, Write, Bash, TodoWrite, MultiEdit, Grep' — appropriate for process documentation and automation.
MCP Risk
Low
No MCP servers are declared in the profile.
No hidden instructions, arbitrary binary execution, or unrestricted network/filesystem access are present.
Profile is a collection of markdown agent instructions without server definitions.