webapp-testing
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to analyze the content of web applications using Playwright tools like
page.content()andpage.screenshot(). This exposes the agent to potentially malicious data that could contain hidden instructions designed to manipulate the agent's behavior. - Ingestion points:
SKILL.mddescribes a pattern where the agent retrieves the DOM content and takes screenshots to identify selectors and plan actions. - Boundary markers: No specific delimiters or safety instructions are provided to help the agent distinguish between application data and its own instructions.
- Capability inventory: The agent has the ability to execute shell commands via
scripts/with_server.pyand run Python scripts. - Sanitization: The skill does not provide mechanisms to sanitize or validate the content retrieved from the web pages before the agent processes it.
- [COMMAND_EXECUTION]: The helper script
scripts/with_server.pyusessubprocess.Popen(shell=True)to start servers andsubprocess.run()to execute test scripts. This gives the agent broad authority to execute shell commands on the host system. - [DYNAMIC_EXECUTION]: The
scripts/with_server.pyscript assembles shell commands from runtime arguments. While necessary for its function as a server manager, this dynamic command assembly creates a surface for command injection if the agent attempts to process untrusted input strings as server commands.
Audit Metadata