skills/c0x12c/ai-toolkit/web-to-prd/Gen Agent Trust Hub

web-to-prd

Pass

Audited by Gen Agent Trust Hub on May 8, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Recommends the installation of recognized tools '@playwright/mcp' and 'firecrawl-mcp' from the official NPM registry to facilitate browser automation.
  • [COMMAND_EXECUTION]: Employs targeted Bash commands to manage Playwright lock files within a dedicated profile directory, preventing session conflicts without affecting user-level processes.
  • [DATA_EXFILTRATION]: Automates the collection of web app features for export to Notion; strictly prohibits the agent from handling passwords or screenshotting login pages to ensure data privacy.
  • [PROMPT_INJECTION]: Incorporates specific directives that forbid automated authentication, ensuring sensitive login tasks remain under manual human control.
  • [PROMPT_INJECTION]: Identified an indirect injection surface inherent in web crawling. Ingestion points: External web content captured via Playwright in 'SKILL.md'. Boundary markers: None explicitly defined. Capability inventory: 'Write' for local storage, 'Bash' for configuration, and Notion integration tools. Sanitization: No content filtering is specified before generation.
  • [SAFE]: The skill's architecture relies on official MCP servers and incorporates multiple human-in-the-loop checkpoints to verify site coverage and data before export.
Audit Metadata
Risk Level
SAFE
Analyzed
May 8, 2026, 03:41 PM
Security Audit — agent-trust-hub — web-to-prd