web-perf
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from external websites and local codebases, which creates a surface for indirect prompt injection where malicious content in a website or file could influence the agent's behavior.
- Ingestion points: The skill ingests untrusted data through
navigate_pageresults, network request details, and local source code files during codebase analysis in SKILL.md. - Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat external content as untrusted data or to ignore instructions embedded within the audited pages.
- Capability inventory: The skill utilizes tools for navigating web pages, analyzing network traffic, taking accessibility snapshots, and reading local filesystem content.
- Sanitization: The instructions do not define any sanitization or validation steps for content retrieved from external URLs before it is processed by the agent.
- [EXTERNAL_DOWNLOADS]: The skill recommends the installation and execution of an external package from the NPM registry to enable its core functionality.
- Evidence: The configuration section in SKILL.md suggests adding
"command": ["npx", "-y", "chrome-devtools-mcp@latest"]to the user's MCP configuration. - Context: While NPM is a well-known service, the recommendation uses an unpinned version (@latest) for a third-party package, which avoids version lock-in and can be a vector for supply chain risks if the upstream package is updated with malicious code.
Audit Metadata