qa-selenium-java-writer

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill generates standardized Selenium Java test code using industry-recognized libraries (Selenium, JUnit 5, AssertJ) and proven design patterns like the Page Object Model (POM).
  • [SAFE]: The documentation explicitly promotes security best practices, including the use of environment variables for base URLs and credentials instead of hardcoding sensitive information.
  • [SAFE]: Dependencies listed in the configuration references are specific, versioned, and sourced from trusted development ecosystems.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an ingestion surface for external data, including test case specifications, manual test designs, and browser-collected data (referenced in SKILL.md). While this creates a surface for indirect prompt injection if the source data contains malicious instructions, the risk is mitigated because the skill's primary purpose is to produce source code for manual review. No automated execution of the generated code or ingested data is performed by the skill itself, and it lacks sanitization or explicit boundary markers for these inputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:38 PM
Security Audit — agent-trust-hub — qa-selenium-java-writer