visual-dev-loop
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
portless,chrome-devtools, andagent-browserfor browser automation and server management. It includes shell commands to start servers (portless myapp next dev) and manage processes (kill $(lsof -ti:PORT)). - [PRIVILEGE_ESCALATION]: Instructions mention that the first run of the
portlesstool requires elevated permissions viasudo portless trustto handle port 443 on macOS/Linux. - [INDIRECT_PROMPT_INJECTION]: The skill represents a surface for indirect prompt injection as it is designed to ingest and inspect external web content via
chrome-devtoolsandagent-browser(e.g.,list_console_messages,take_snapshot). Malicious content in the web pages being inspected could attempt to influence the agent's behavior. - Ingestion points: Web page console messages, accessibility snapshots, and network request logs via
chrome-devtoolsandagent-browserinSKILL.md. - Boundary markers: None identified in the prompt templates.
- Capability inventory: Subprocess execution for
portlessandkillcommands, file reads/writes for screenshots and diffs, and network operations through browser automation. - Sanitization: None specified for the data read from browser snapshots or console logs.
Audit Metadata