slop-eval

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes system utilities such as curl, wget, and npx playwright screenshot to fetch HTML and capture visual evidence from target designs. It also executes a bundled Python script scripts/score.py to perform deterministic scoring based on detected design flaws.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection because it is designed to ingest and process untrusted content from external websites and codebases.
  • Ingestion points: The target parameter in SKILL.md allows users to provide live URLs or code paths which are then crawled and analyzed by the agent.
  • Boundary markers: None identified; the instructions lack explicit delimiters to separate the evaluation instructions from text content found on the target websites.
  • Capability inventory: Network access (browser automation), file system writes (generating reports), and local script execution.
  • Sanitization: The skill does not describe specific sanitization or filtering for the textual content of the audited designs, which could potentially contain malicious prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 08:20 AM
Security Audit — agent-trust-hub — slop-eval