webapp-testing
Fail
Audited by Gen Agent Trust Hub on Apr 24, 2026
Risk Level: HIGHCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/with_server.pyexecutes commands provided via the--serverargument usingsubprocess.Popenwithshell=True, which is vulnerable to command injection if the input strings contain shell metacharacters like pipes, semicolons, or ampersands. - [COMMAND_EXECUTION]: The script
scripts/with_server.pyexecutes arbitrary user-supplied commands throughsubprocess.run, which allows for the execution of any system command accessible in the agent's environment. - [EXTERNAL_DOWNLOADS]: The skill documentation and scripts facilitate the download of the
playwrightlibrary and its associated browser binaries from Microsoft's official package registries and infrastructure. - [PROMPT_INJECTION]: The
SKILL.mdfile contains an extensive persona block that instructs the agent to act as a 'senior code reviewer' and includes a checklist with deceptive safety claims such as 'Zero critical security issues verified' and 'No high-priority vulnerabilities found,' which can interfere with the agent's objective security auditing capabilities and safety protocols. - [PROMPT_INJECTION]: The skill ingests untrusted data from external URLs via Playwright in
scripts/playwright_runner.pyandexamples/console_logging.pywithout implementing sanitization or boundary markers; when combined with the subprocess execution capabilities inscripts/with_server.py, this creates a surface for indirect prompt injection where a malicious website could attempt to trigger system commands.
Recommendations
- AI detected serious security threats
Audit Metadata