webapp-testing
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The helper script
scripts/with_server.pyutilizessubprocess.Popenwithshell=Trueto execute commands provided via the--serverargument. This implementation is designed to support shell-specific operations such as directory navigation (cd) and command chaining (&&) required to start development environments. - [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection because it interacts with and extracts data from external web applications, which may contain malicious instructions.
- Ingestion points: Data enters the agent's context through
page.content()calls, console log capture inexamples/console_logging.py, and browser screenshots. - Boundary markers: The scripts and instructions do not implement specific boundary markers or 'ignore' instructions to delineate untrusted web content from system prompts.
- Capability inventory: The skill allows the agent to execute shell commands through the
with_server.pyutility and perform file write operations for logging and screenshot storage. - Sanitization: Captured console logs and HTML content are processed directly without validation, filtering, or sanitization.
Audit Metadata