e2e-testing

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for the agent to perform operational tasks including software installation (Playwright) and the execution of browser automation tests across multiple phases.
  • [EXTERNAL_DOWNLOADS]: The skill references an external GitHub repository (https://github.com/sickn33/antigravity-awesome-skills) as its source origin and directs the agent to install the Playwright library from a public package registry.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by processing user-defined tasks and repository context within its workflow.
  • Ingestion points: The SKILL.md file defines multiple workflow examples that incorporate user-provided input through placeholders.
  • Boundary markers: The skill lacks explicit delimiters or instructions that would signal the agent to treat the user-provided task descriptions as untrusted or isolated data.
  • Capability inventory: The agent is instructed to perform high-capability actions such as installing software, creating directories, and configuring CI/CD workflows (e.g., GitHub Actions).
  • Sanitization: No evidence of sanitization, validation, or escaping of user-provided content was found before its interpolation into agent prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 11:32 AM
Security Audit — agent-trust-hub — e2e-testing