best-practices-cots
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The
run.shscript executes a local Node.js scanner (scanner.cjs) to perform UI audits. TheSKILL.mdalso documents a fix plan feature that can execute shell commands to verify if a violation is resolved (Definition of Done), but this is limited to running the skill's own scanner and checking its output viajq. - [REMOTE_CODE_EXECUTION]: The skill uses a headless browser (Chrome via CDP) to interact with target URLs provided by the user. While this involves executing JavaScript within a sandboxed browser environment to measure UI properties, it is the primary intended function of a compliance scanner.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external websites (URLs) and processes it through a Visual Language Model (VLM). While an attacker-controlled website could theoretically attempt to influence the VLM's analysis through visual cues or text, the risk is localized to the compliance report generation (e.g., forcing a 'PASS' status) and does not grant broader agent control.
Audit Metadata