CtrlK
BlogDocsLog inGet started
Tessl Logo

testland/helm-chart-tester

Configures helm-unittest for Helm chart unit testing - installs the `helm-unittest` plugin, authors `tests/*.yaml` per template, asserts on rendered manifests (`isKind`, `equal`, `matchRegex`, snapshots), plus `helm lint` and `helm template` render testing. Use to verify a chart's template logic and rendered shape; this is unit-level correctness testing, not security scanning - to enforce policy on rendered manifests use policy-as-code-runner, and to scan charts for misconfigurations use checkov-policy or trivy-config.

72

Quality

90%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Overview
Quality
Evals
Security
Files

Low

Low-risk findings.

1 low severity finding. Worth noting, but not necessarily harmful.

Low

W012: Unverifiable external dependency detected (runtime URL that controls agent).

What this means

The skill fetches instructions or code from an external URL at runtime, and the fetched content directly controls the agent’s prompts or executes code. This dynamic dependency allows the external source to modify the agent’s behavior without any changes to the skill itself.

Why it was flagged

The skill instructs runtime installation of a Helm plugin via "helm plugin install https://github.com/helm-unittest/helm-unittest", which fetches and installs remote code from that URL (executing plugin code) and is required to run the tests.

Where we found it

helm-unittest/helm-unittest

dependency · 2 sites

The plugin instructs the agent to run `helm plugin install` from a remote GitHub repository, fetching and executing unverified remote code at runtime.

SKILL.md

25

helm plugin install https://github.com/helm-unittest/helm-unittest

SKILL.md

170

- run: helm plugin install https://github.com/helm-unittest/helm-unittest

actions/checkout@v5

dependency · 1 site

The CI integration section instructs use of a GitHub Action (actions/checkout@v5), which is a hosted remote dependency executed at runtime.

SKILL.md

167

- uses: actions/checkout@v5

azure/setup-helm@v4

dependency · 1 site

The CI integration section instructs use of a third-party GitHub Action (azure/setup-helm@v4), which fetches and runs remote code at runtime.

SKILL.md

168

- uses: azure/setup-helm@v4

Report incorrect finding
Audited
Security analysis
Snyk