website-visual-testing

Pass

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes pty_spawn and pty_read to manage the lifecycle of local development servers, such as Vite and Nuxt. This is standard functionality for the intended use case of testing local applications.
  • [EXTERNAL_DOWNLOADS]: SOURCES.md contains informational links to external QA resources, industry blogs, and documentation for the agent-browser tool. These are non-executable references to established technical sites and official repositories.
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface as it involves the agent reading and processing content from external websites via agent-browser. Evidence: (1) Ingestion points: Browser snapshots and navigation in agent-browser. (2) Boundary markers: None identified. (3) Capability inventory: Local process spawning via pty_spawn. (4) Sanitization: None specified for external DOM content. The risk is mitigated by the skill's focus on visual verification and structured snapshots.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 4, 2026, 08:25 AM
Security Audit — agent-trust-hub — website-visual-testing