Cypress Agent Skill
PassAudited by VirusTotal on May 11, 2026.
Findings (1)
The skill bundle contains extensive misinformation regarding the Cypress testing framework, including references to non-existent versions (v15.x) and fake APIs such as `cy.env()`, `Cypress.expose()`, and `cy.prompt()`. The instructions in `SKILL.md` and `references/config.md` explicitly direct AI agents to deprecate standard, functional APIs (`Cypress.env()`) and enforce configurations (`allowCypressEnv: false`) that would break legitimate testing environments. While the `README.md` promotes a risky `curl | bash` installation pattern, there is no clear evidence of intentional data exfiltration or backdoor persistence, suggesting the bundle is designed to mislead or disrupt rather than directly infect.
