visual-qa

Pass

Audited by Gen Agent Trust Hub on Aug 9, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Recommends the installation of the agent-browser utility from the Vercel Labs repository for web page captures.- [COMMAND_EXECUTION]: Uses local Node.js scripts (visual-qa.mjs) to perform pixel-by-pixel comparisons and TUI alignment validation.- [PROMPT_INJECTION]: Explicitly instructs the agent to treat all user-provided reference data as untrusted content, mitigating indirect prompt injection from visual assets. Ingestion points: Reference packets (images, annotations); Boundary markers: Explicit instructions to ignore embedded commands; Capability inventory: Subagent spawning and local script execution; Sanitization: Guidance for manual redaction of sensitive data.- [DATA_EXFILTRATION]: Instructions are provided to redact secrets, tokens, and customer data from reference packets before processing, reducing the risk of accidental exposure of credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 9, 2026, 12:43 PM
Security Audit — agent-trust-hub — visual-qa