webapp-testing
Warn
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The helper script
scripts/with_server.pyusessubprocess.Popenwithshell=Trueto execute commands provided via the--serverargument. This implementation allows for shell metacharacter injection and the execution of arbitrary shell logic. - [PROMPT_INJECTION]: The
SKILL.mdfile contains instructions that tell the agent to 'DO NOT read the source' of helper scripts and to use them as 'black boxes'. This instruction discourages the agent from auditing the tools it uses, effectively concealing the dangerousshell=Trueimplementation from the agent's safety oversight. - [COMMAND_EXECUTION]: Risk surface for Indirect Prompt Injection.
- Ingestion points: The agent is instructed to interact with local web applications using Playwright, ingesting rendered HTML content, console logs, and DOM state (SKILL.md).
- Boundary markers: Absent. There are no instructions or delimiters used to separate the tested application's data from the agent's instructions.
- Capability inventory: The skill provides arbitrary shell command execution through
scripts/with_server.py. - Sanitization: Absent. No sanitization is performed on inputs before they are passed to the shell execution sinks.
Audit Metadata