workflow-e2e
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data, including Chrome DevTools recording JSON files and git diffs, which could potentially contain malicious instructions targeting the agent.
- Ingestion points: The skill explicitly loads recording files (JSON format) and reads git diffs to determine testing logic as described in SKILL.md.
- Boundary markers: There are no explicit delimiters or instructions provided to the agent to ignore or sanitize embedded instructions within these ingested files.
- Capability inventory: The skill possesses the capability to spawn sub-agents (
spawn_agent), execute scripts (convert-recording.ts), and perform filesystem operations. - Sanitization: No evidence of sanitization, validation, or filtering of the external content was found in the instructions.
- [DYNAMIC_EXECUTION]: The workflow involves generating and executing code based on external recording data.
- Evidence: The protocol for
--source=recordinginstructs the agent to "Run convert-recording.ts to generate initial test file" and subsequently enhance and run that code. - Context: While this is standard for E2E automation tools, the generation of executable scripts from external data sources presents a managed risk if the generator does not safely handle the input.
Audit Metadata