test-interactions
Warn
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: MEDIUMCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The file
test_interactions.pycontains a hardcoded Bearer tokensk-dev-proxy-123used for authentication when calling a local LLM proxy service atlocalhost:4001. While likely a development placeholder, hardcoded tokens are flagged for review. - [EXTERNAL_DOWNLOADS]: In
cdp_client.py, the skill attempts to dynamically install thewebsocket-clientpackage viauv pip installif the module is missing. Runtime dependency installation is an unverifiable risk. - [COMMAND_EXECUTION]: The skill frequently uses the
subprocessmodule to manage browser processes, execute media processing viaffmpeg, and invoke composed skills (such asticketandreview-design). These are legitimate uses for the skill's purpose but involve high-risk command execution. - [PROMPT_INJECTION]: The skill ingests untrusted data from the DOM of URLs provided during testing. This creates an indirect prompt injection surface. However, the risk is mitigated by the skill's architecture, which uses deterministic assertions for PASS/FAIL verdicts and only uses the LLM for additive visual commentary.
Audit Metadata