visual-qa

Pass

Audited by Gen Agent Trust Hub on Oct 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from UI surfaces (screenshots, text, terminal logs) through AI subagents. Ingestion points: defined in SKILL.md for reference packets and live captures. Boundary markers: present in SKILL.md as instructions to treat UI content as data, not instructions. Capability inventory: includes spawn_agent for oracles, node for local script execution, and browser automation via omowright. Sanitization: includes mandatory redaction of secrets from all artifacts.
  • [COMMAND_EXECUTION]: The skill executes a local Node.js script (scripts/visual-qa.mjs) to perform image comparisons and terminal layout checks. This script is bundled from the included TypeScript source code and relies on built-in Node.js modules.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 6, 2026, 02:55 PM