webapp-testing

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The utility script scripts/with_server.py uses subprocess.Popen with shell=True to execute server startup commands provided as arguments. This is designed to support development commands that involve shell features like cd or &&.
  • [COMMAND_EXECUTION]: The scripts/with_server.py script executes a user-provided automation command after verifying that the specified servers are active and reachable.
  • [SAFE]: The skill identifies an indirect prompt injection surface as it interacts with and reads the content of local web applications; however, this is inherent to its primary purpose of web testing and reconnaissance.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 09:04 PM
Security Audit — agent-trust-hub — webapp-testing