skills/grupous/gpus/webapp-testing/Gen Agent Trust Hub

webapp-testing

Fail

Audited by Gen Agent Trust Hub on Apr 24, 2026

Risk Level: HIGHCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/with_server.py executes commands provided via the --server argument using subprocess.Popen with shell=True, which is vulnerable to command injection if the input strings contain shell metacharacters like pipes, semicolons, or ampersands.
  • [COMMAND_EXECUTION]: The script scripts/with_server.py executes arbitrary user-supplied commands through subprocess.run, which allows for the execution of any system command accessible in the agent's environment.
  • [EXTERNAL_DOWNLOADS]: The skill documentation and scripts facilitate the download of the playwright library and its associated browser binaries from Microsoft's official package registries and infrastructure.
  • [PROMPT_INJECTION]: The SKILL.md file contains an extensive persona block that instructs the agent to act as a 'senior code reviewer' and includes a checklist with deceptive safety claims such as 'Zero critical security issues verified' and 'No high-priority vulnerabilities found,' which can interfere with the agent's objective security auditing capabilities and safety protocols.
  • [PROMPT_INJECTION]: The skill ingests untrusted data from external URLs via Playwright in scripts/playwright_runner.py and examples/console_logging.py without implementing sanitization or boundary markers; when combined with the subprocess execution capabilities in scripts/with_server.py, this creates a surface for indirect prompt injection where a malicious website could attempt to trigger system commands.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Apr 24, 2026, 09:21 AM
Security Audit — agent-trust-hub — webapp-testing