visual-qa

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted external data in the form of UI screenshots and terminal captures, which are then interpolated into subagent prompts for analysis. \n
  • Ingestion points: UI captures are read via readFileSync in scripts/cli.ts and provided to oracle agents in Step 3 of SKILL.md.\n
  • Boundary markers: The prompt templates for Pass A and Pass B lack explicit boundary markers or instructions to disregard potential instructions embedded within the captures.\n
  • Capability inventory: The skill can spawn subagents using the task tool and execute local shell commands via bun.\n
  • Sanitization: There is no evidence of data sanitization or escaping of the ingested UI content before it is added to the prompt context.\n- [EXTERNAL_DOWNLOADS]: The skill instructions recommend installing agent-browser from the Vercel Labs GitHub repository. This involves downloading a managed browser environment from a well-known and trusted organization.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 11:37 AM
Security Audit — agent-trust-hub — visual-qa