webapp-testing
Pass
Audited by Gen Agent Trust Hub on Jul 14, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The utility script
scripts/with_server.pyusessubprocess.Popenwithshell=Trueto execute server startup commands provided as arguments. This is designed to support development commands that involve shell features likecdor&&. - [COMMAND_EXECUTION]: The
scripts/with_server.pyscript executes a user-provided automation command after verifying that the specified servers are active and reachable. - [SAFE]: The skill identifies an indirect prompt injection surface as it interacts with and reads the content of local web applications; however, this is inherent to its primary purpose of web testing and reconnaissance.
Audit Metadata