ui-demo
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill has a surface for indirect prompt injection because it ingests untrusted data from external web applications during the 'Discover' phase to generate subsequent automation scripts.
- Ingestion points: Element metadata (tags, placeholders, text content) is extracted from the DOM of target pages using
page.evaluatein the discovery section of SKILL.md. - Boundary markers: The skill does not explicitly define delimiters or instructions for the agent to ignore potentially malicious commands embedded within the text content of the target application's UI elements.
- Capability inventory: The skill generates and executes Node.js scripts using
playwrightto control a browser, including file system access (fs.copyFileSync) and network navigation (page.goto). - Sanitization: The skill extracts text content using
.textContent?.trim().substring(0, 40), which limits the length of ingested data but does not perform semantic sanitization to prevent the agent from interpreting embedded instructions. - [DYNAMIC_EXECUTION]: The skill utilizes dynamic execution patterns to perform its core UI automation and recording tasks.
- Script generation: The 'Record' phase involves generating a standalone Node.js script (
demo-script.cjs) from templates provided in the skill documentation. - Browser script injection: The skill uses
page.evaluatemultiple times to inject and execute JavaScript within the browser context to implement cursor overlays, subtitle bars, and DOM element discovery.
Audit Metadata