done
Pass
Audited by Gen Agent Trust Hub on Jul 11, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill instructs the agent to process potentially untrusted external data, such as UI content via Playwright and project files during validation, creating a surface for indirect prompt injection.
- Ingestion points: Project files, UI content (Gate 2), and validation logs (Gate 1).
- Boundary markers: None explicitly defined to isolate processed data from agent instructions.
- Capability inventory: File system operations (deleting scratch files), process management (
kill), and package execution (pnpx). - Sanitization: No explicit sanitization or validation of the processed data is described.
- [COMMAND_EXECUTION]: The skill directs the agent to use powerful shell commands for environment cleanup and process management.
- Evidence: Use of
killandkill -9to terminate test servers, following a verification process usinglsofandpsto identify the correct PID. - Evidence: Use of
rm -rfto clear specific cache directories such asnode_modules/.viteandnode_modules/.cache/storybookto resolve test flakiness. - [EXTERNAL_DOWNLOADS]: The skill utilizes a package runner to execute a specific linting tool from a public registry.
- Evidence: Execution of
pnpx node-actionlint, which downloads and runs thenode-actionlintpackage from the NPM registry.
Audit Metadata