test-interactions

Warn

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: MEDIUMCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The file test_interactions.py contains a hardcoded Bearer token sk-dev-proxy-123 used for authentication when calling a local LLM proxy service at localhost:4001. While likely a development placeholder, hardcoded tokens are flagged for review.
  • [EXTERNAL_DOWNLOADS]: In cdp_client.py, the skill attempts to dynamically install the websocket-client package via uv pip install if the module is missing. Runtime dependency installation is an unverifiable risk.
  • [COMMAND_EXECUTION]: The skill frequently uses the subprocess module to manage browser processes, execute media processing via ffmpeg, and invoke composed skills (such as ticket and review-design). These are legitimate uses for the skill's purpose but involve high-risk command execution.
  • [PROMPT_INJECTION]: The skill ingests untrusted data from the DOM of URLs provided during testing. This creates an indirect prompt injection surface. However, the risk is mitigated by the skill's architecture, which uses deterministic assertions for PASS/FAIL verdicts and only uses the LLM for additive visual commentary.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 26, 2026, 06:01 PM
Security Audit — agent-trust-hub — test-interactions