ui-demo

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill has a surface for indirect prompt injection because it ingests untrusted data from external web applications during the 'Discover' phase to generate subsequent automation scripts.
  • Ingestion points: Element metadata (tags, placeholders, text content) is extracted from the DOM of target pages using page.evaluate in the discovery section of SKILL.md.
  • Boundary markers: The skill does not explicitly define delimiters or instructions for the agent to ignore potentially malicious commands embedded within the text content of the target application's UI elements.
  • Capability inventory: The skill generates and executes Node.js scripts using playwright to control a browser, including file system access (fs.copyFileSync) and network navigation (page.goto).
  • Sanitization: The skill extracts text content using .textContent?.trim().substring(0, 40), which limits the length of ingested data but does not perform semantic sanitization to prevent the agent from interpreting embedded instructions.
  • [DYNAMIC_EXECUTION]: The skill utilizes dynamic execution patterns to perform its core UI automation and recording tasks.
  • Script generation: The 'Record' phase involves generating a standalone Node.js script (demo-script.cjs) from templates provided in the skill documentation.
  • Browser script injection: The skill uses page.evaluate multiple times to inject and execute JavaScript within the browser context to implement cursor overlays, subtitle bars, and DOM element discovery.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 02:38 AM
Security Audit — agent-trust-hub — ui-demo