app-navigator

Warn

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: MEDIUMCREDENTIALS_UNSAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill instructs the agent to request sensitive login information (email and password) from the user and save it to a plaintext markdown file at ~/.claude/projects/<project>/memory/reference_local_auth.md. While the skill attempts to restrict access using chmod 600, storing credentials in a standard document format within the project directory creates a risk of local credential exposure.
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to execute system-level commands, including modifying file system permissions (chmod), performing network reachability checks via curl, and potentially starting local development servers (e.g., npm run dev). These operations grant the skill significant control over the host environment.
  • [PROMPT_INJECTION]: By navigating web applications and capturing snapshots via Playwright tools, the skill creates an indirect prompt injection surface. Malicious text or instructions hidden within the target application's UI could be ingested and interpreted by the agent during the mapping and documentation process.
  • Ingestion points: Browser snapshots and page metadata captured through mcp__playwright__browser_snapshot and mcp__playwright__browser_take_screenshot.
  • Boundary markers: No specific delimiters or "ignore instructions" warnings are defined for the data retrieved from the web browser.
  • Capability inventory: The skill possesses extensive capabilities including file system read/write (Read, Write), network testing (curl), shell command execution (Bash), and browser automation (mcp__playwright__*).
  • Sanitization: No explicit sanitization or validation of the content retrieved from external web pages is implemented before it is processed by the agent or saved to documentation.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 20, 2026, 05:49 AM
Security Audit — agent-trust-hub — app-navigator