workflow-e2e

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data, including Chrome DevTools recording JSON files and git diffs, which could potentially contain malicious instructions targeting the agent.
  • Ingestion points: The skill explicitly loads recording files (JSON format) and reads git diffs to determine testing logic as described in SKILL.md.
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to ignore or sanitize embedded instructions within these ingested files.
  • Capability inventory: The skill possesses the capability to spawn sub-agents (spawn_agent), execute scripts (convert-recording.ts), and perform filesystem operations.
  • Sanitization: No evidence of sanitization, validation, or filtering of the external content was found in the instructions.
  • [DYNAMIC_EXECUTION]: The workflow involves generating and executing code based on external recording data.
  • Evidence: The protocol for --source=recording instructs the agent to "Run convert-recording.ts to generate initial test file" and subsequently enhance and run that code.
  • Context: While this is standard for E2E automation tools, the generation of executable scripts from external data sources presents a managed risk if the generator does not safely handle the input.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 08:23 PM
Security Audit — agent-trust-hub — workflow-e2e