webapp-testing

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The helper script scripts/with_server.py utilizes subprocess.Popen with shell=True to execute commands provided via the --server argument. This implementation is designed to support shell-specific operations such as directory navigation (cd) and command chaining (&&) required to start development environments.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection because it interacts with and extracts data from external web applications, which may contain malicious instructions.
  • Ingestion points: Data enters the agent's context through page.content() calls, console log capture in examples/console_logging.py, and browser screenshots.
  • Boundary markers: The scripts and instructions do not implement specific boundary markers or 'ignore' instructions to delineate untrusted web content from system prompts.
  • Capability inventory: The skill allows the agent to execute shell commands through the with_server.py utility and perform file write operations for logging and screenshot storage.
  • Sanitization: Captured console logs and HTML content are processed directly without validation, filtering, or sanitization.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:52 PM
Security Audit — agent-trust-hub — webapp-testing