ui-demo
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill interacts with and extracts data from external web pages to facilitate automated recording, creating a surface for potential injection.
- Ingestion points: During the 'Discover' phase, the skill uses
page.evaluate()to retrieve metadata, labels, and text content from interactive elements on target web pages (SKILL.md). - Boundary markers: The instructions do not define clear boundaries or 'ignore' directives for the data retrieved from external pages before it is processed by the agent to generate scripts.
- Capability inventory: The skill utilizes Playwright for full browser automation (navigation, clicking, typing) and the Node.js
fsmodule for file system operations (saving videos). - Sanitization: There is no evidence of sanitization or filtering of the text extracted from the DOM (e.g., placeholders, button text) before it is used to inform the agent's next steps.
Audit Metadata