add-webcodecs-bug

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill performs routine maintenance of project documentation by reading local files and visiting official browser bug trackers (Chromium, WebKit, and Mozilla). These are well-known and reputable services.
  • [SAFE]: The skill interacts with external untrusted data from bug trackers, which is an attack surface for indirect prompt injection. However, the risk is assessed as safe because the agent is constrained to extracting specific metadata for a table.
  • Ingestion points: External issue tracker URLs (Workflow Step 2).
  • Boundary markers: None present to isolate external content from instructions.
  • Capability inventory: File read and write access to packages/docs/docs/mediabunny/webcodecs-bugs.mdx.
  • Sanitization: No explicit sanitization of issue titles or descriptions is performed before they are written to the local MDX file.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 01:13 PM
Security Audit — agent-trust-hub — add-webcodecs-bug