skills/alexanderop/skills/qa-explore/Gen Agent Trust Hub

qa-explore

Warn

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill instructs the agent to search for and read sensitive local files, specifically mentioning .env.local and brain/local/test-credentials.md, to retrieve authentication tokens and credentials for use in the browser session.
  • [COMMAND_EXECUTION]: The skill executes arbitrary shell commands defined in the project's package.json (such as pnpm dev, npm run dev, or yarn dev) and utilizes the agent-browser tool to manipulate the UI.
  • [PROMPT_INJECTION]: The skill ingests data from untrusted or external sources including browser accessibility trees, console logs, and project-specific documentation files (e.g., CLAUDE.md). This creates an indirect prompt injection surface (Category 8) because the agent processes this content to make decisions without the use of boundary markers or sanitization.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 1, 2026, 11:53 PM
Security Audit — agent-trust-hub — qa-explore