qa-browser-automation

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: Automated scanners flagged patterns involving curl piped to Python. A manual review of the skill's SKILL.md and accessibility_auditor.py script confirms these are legitimate usage examples (e.g., curl -s https://example.com | python scripts/accessibility_auditor.py -). The scripts process the piped content as raw HTML data for auditing purposes and do not execute it as code. The target domain 'example.com' is a well-known placeholder for documentation.
  • [INDIRECT_PROMPT_INJECTION]: The skill represents a surface for indirect prompt injection as it ingests and processes external HTML content and QA findings data.
  • Ingestion points: accessibility_auditor.py reads data from standard input or files; qa_health_scorer.py and test_report_generator.py ingest JSON findings files.
  • Boundary markers: The skill does not currently implement specific boundary markers to delimit untrusted web content from instructions.
  • Capability inventory: The scripts perform local file writes for reports and baselines but do not contain dangerous capabilities such as eval(), exec(), or arbitrary network communication.
  • Sanitization: HTML content is processed using Python's standard html.parser, which is a structural parser that does not execute embedded scripts or styles.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 04:25 AM
Security Audit — agent-trust-hub — qa-browser-automation