website-visual-testing
Pass
Audited by Gen Agent Trust Hub on Aug 4, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes
pty_spawnandpty_readto manage the lifecycle of local development servers, such as Vite and Nuxt. This is standard functionality for the intended use case of testing local applications. - [EXTERNAL_DOWNLOADS]:
SOURCES.mdcontains informational links to external QA resources, industry blogs, and documentation for theagent-browsertool. These are non-executable references to established technical sites and official repositories. - [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface as it involves the agent reading and processing content from external websites via
agent-browser. Evidence: (1) Ingestion points: Browser snapshots and navigation inagent-browser. (2) Boundary markers: None identified. (3) Capability inventory: Local process spawning viapty_spawn. (4) Sanitization: None specified for external DOM content. The risk is mitigated by the skill's focus on visual verification and structured snapshots.
Audit Metadata