qa-engineer

Pass

Audited by Gen Agent Trust Hub on May 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses dynamic context injection via the exclamation-mark-and-backtick syntax to load local configuration and protocol files like ux-protocol.md and .production-grade.yaml. These commands are used solely to fetch project-specific instructions and do not execute user-provided code.
  • [EXTERNAL_DOWNLOADS]: References the installation of standard industry tools from public registries, including @playwright/test, @midscene/web, and @axe-core/playwright.
  • [REMOTE_CODE_EXECUTION]: Mentions using npx skills add web-infra-dev/midscene-skills to incorporate third-party vision-testing capabilities. This is consistent with the skill's purpose of providing advanced QA automation.
  • [PROMPT_INJECTION]: The skill contains an indirect prompt injection surface inherent to its function of processing requirements to generate code. Ingestion points: Reads BRD/PRD and source code from the repository. Boundary markers: Absent; instructions do not explicitly tell the agent to ignore instructions embedded in the requirements. Capability inventory: Generates and writes executable test scripts and CI/CD workflows. Sanitization: No explicit content validation of input documents.
Audit Metadata
Risk Level
SAFE
Analyzed
May 1, 2026, 08:02 AM
Security Audit — agent-trust-hub — qa-engineer