app-navigator
Warn
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: MEDIUMCREDENTIALS_UNSAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill instructs the agent to request sensitive login information (email and password) from the user and save it to a plaintext markdown file at
~/.claude/projects/<project>/memory/reference_local_auth.md. While the skill attempts to restrict access usingchmod 600, storing credentials in a standard document format within the project directory creates a risk of local credential exposure. - [COMMAND_EXECUTION]: The skill utilizes the
Bashtool to execute system-level commands, including modifying file system permissions (chmod), performing network reachability checks viacurl, and potentially starting local development servers (e.g.,npm run dev). These operations grant the skill significant control over the host environment. - [PROMPT_INJECTION]: By navigating web applications and capturing snapshots via Playwright tools, the skill creates an indirect prompt injection surface. Malicious text or instructions hidden within the target application's UI could be ingested and interpreted by the agent during the mapping and documentation process.
- Ingestion points: Browser snapshots and page metadata captured through
mcp__playwright__browser_snapshotandmcp__playwright__browser_take_screenshot. - Boundary markers: No specific delimiters or "ignore instructions" warnings are defined for the data retrieved from the web browser.
- Capability inventory: The skill possesses extensive capabilities including file system read/write (
Read,Write), network testing (curl), shell command execution (Bash), and browser automation (mcp__playwright__*). - Sanitization: No explicit sanitization or validation of the content retrieved from external web pages is implemented before it is processed by the agent or saved to documentation.
Audit Metadata