webapp-testing

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to analyze the content of web applications using Playwright tools like page.content() and page.screenshot(). This exposes the agent to potentially malicious data that could contain hidden instructions designed to manipulate the agent's behavior.
  • Ingestion points: SKILL.md describes a pattern where the agent retrieves the DOM content and takes screenshots to identify selectors and plan actions.
  • Boundary markers: No specific delimiters or safety instructions are provided to help the agent distinguish between application data and its own instructions.
  • Capability inventory: The agent has the ability to execute shell commands via scripts/with_server.py and run Python scripts.
  • Sanitization: The skill does not provide mechanisms to sanitize or validate the content retrieved from the web pages before the agent processes it.
  • [COMMAND_EXECUTION]: The helper script scripts/with_server.py uses subprocess.Popen(shell=True) to start servers and subprocess.run() to execute test scripts. This gives the agent broad authority to execute shell commands on the host system.
  • [DYNAMIC_EXECUTION]: The scripts/with_server.py script assembles shell commands from runtime arguments. While necessary for its function as a server manager, this dynamic command assembly creates a surface for command injection if the agent attempts to process untrusted input strings as server commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:19 AM
Security Audit — agent-trust-hub — webapp-testing