visual-qa
Pass
Audited by Gen Agent Trust Hub on Aug 9, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Recommends the installation of the
agent-browserutility from the Vercel Labs repository for web page captures.- [COMMAND_EXECUTION]: Uses local Node.js scripts (visual-qa.mjs) to perform pixel-by-pixel comparisons and TUI alignment validation.- [PROMPT_INJECTION]: Explicitly instructs the agent to treat all user-provided reference data as untrusted content, mitigating indirect prompt injection from visual assets. Ingestion points: Reference packets (images, annotations); Boundary markers: Explicit instructions to ignore embedded commands; Capability inventory: Subagent spawning and local script execution; Sanitization: Guidance for manual redaction of sensitive data.- [DATA_EXFILTRATION]: Instructions are provided to redact secrets, tokens, and customer data from reference packets before processing, reducing the risk of accidental exposure of credentials.
Audit Metadata