webapp-testing
Warn
Audited by Gen Agent Trust Hub on Mar 18, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/with_server.pyusessubprocess.Popen(shell=True)to execute server start commands provided as command-line arguments. This implementation is vulnerable to shell injection if the agent passes unvalidated or maliciously crafted strings to the script. - [PROMPT_INJECTION]: The skill possesses a significant indirect prompt injection attack surface. It is designed to navigate to external URLs and extract data such as page titles, headings, and link text using Playwright. This untrusted data is returned to the agent without sanitization or protective boundary markers.
- Ingestion points: Untrusted data enters the agent context through
scripts/playwright_runner.pyand thebrowser_subagenttool which read web content. - Boundary markers: There are no delimiters or 'ignore' instructions wrapping the external content in the skill's workflows.
- Capability inventory: The skill is explicitly granted
Bashaccess in its metadata and includes scripts capable of spawning subprocesses. - Sanitization: The scripts do not perform any escaping or validation of the text retrieved from the target web pages before presenting it to the agent.
Audit Metadata