best-practices-cots

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The run.sh script executes a local Node.js scanner (scanner.cjs) to perform UI audits. The SKILL.md also documents a fix plan feature that can execute shell commands to verify if a violation is resolved (Definition of Done), but this is limited to running the skill's own scanner and checking its output via jq.
  • [REMOTE_CODE_EXECUTION]: The skill uses a headless browser (Chrome via CDP) to interact with target URLs provided by the user. While this involves executing JavaScript within a sandboxed browser environment to measure UI properties, it is the primary intended function of a compliance scanner.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external websites (URLs) and processes it through a Visual Language Model (VLM). While an attacker-controlled website could theoretically attempt to influence the VLM's analysis through visual cues or text, the risk is localized to the compliance report generation (e.g., forcing a 'PASS' status) and does not grant broader agent control.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — best-practices-cots