project-guide-validation
Pass
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill instructions direct the agent to use the
run_commandtool to start a local HTTP server (e.g.,python3 -m http.serverornpx http-server). This is a necessary step to serve thedemo.htmlfile so it can be accessed by the DevTools MCP for automated testing. - [EXTERNAL_DOWNLOADS]: The protocol mentions using
npx http-server, which involves the automated download and execution of thehttp-serverutility from the npm registry. This is a well-known and standard development tool. - [PROMPT_INJECTION]: The skill processes external, untrusted content from project files such as
guide.mdanddemo.htmlto perform its validation tasks.- Ingestion points: Content is read from
guide.md,demo.html, andexpectations.mdlocated in the local workspace. - Boundary markers: The instructions do not specify the use of delimiters or specific warnings to ignore instructions that might be embedded within the files being validated.
- Capability inventory: The agent has the ability to execute shell commands (via
run_command) and interact with a browser instance (viachrome-devtools-mcp). - Sanitization: The skill does not describe any specific sanitization or filtering of the content read from the target files before it is processed.
- Ingestion points: Content is read from
Audit Metadata