visual-dev-loop

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses portless, chrome-devtools, and agent-browser for browser automation and server management. It includes shell commands to start servers (portless myapp next dev) and manage processes (kill $(lsof -ti:PORT)).
  • [PRIVILEGE_ESCALATION]: Instructions mention that the first run of the portless tool requires elevated permissions via sudo portless trust to handle port 443 on macOS/Linux.
  • [INDIRECT_PROMPT_INJECTION]: The skill represents a surface for indirect prompt injection as it is designed to ingest and inspect external web content via chrome-devtools and agent-browser (e.g., list_console_messages, take_snapshot). Malicious content in the web pages being inspected could attempt to influence the agent's behavior.
  • Ingestion points: Web page console messages, accessibility snapshots, and network request logs via chrome-devtools and agent-browser in SKILL.md.
  • Boundary markers: None identified in the prompt templates.
  • Capability inventory: Subprocess execution for portless and kill commands, file reads/writes for screenshots and diffs, and network operations through browser automation.
  • Sanitization: None specified for the data read from browser snapshots or console logs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 02:38 AM
Security Audit — agent-trust-hub — visual-dev-loop