webapp-testing
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/with_server.pyusessubprocess.Popenwithshell=Trueto start server commands provided as command-line arguments. While this is a functional requirement for supporting complex commands (e.g., usingcdand&&), it provides a powerful execution primitive that could be misused if the agent is influenced by malicious input. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and act upon content from external web applications during testing, creating an attack surface for indirect prompt injection.
- Ingestion points: The skill instructions in
SKILL.mdand the exampleexamples/element_discovery.pydirect the agent to inspect the rendered DOM, capture page content, and identify UI selectors from live web pages. - Boundary markers: There are no explicit instructions or delimiters defined to help the agent distinguish between its own system instructions and potentially malicious text embedded within the web pages it processes.
- Capability inventory: The skill possesses significant capabilities including arbitrary shell command execution via
scripts/with_server.pyand file writing (screenshots and log files) inexamples/console_logging.pyandexamples/element_discovery.py. - Sanitization: There is no evidence of sanitization or filtering of the content retrieved from web pages before the agent uses it to decide on subsequent automation actions.
Audit Metadata