webapp-testing

Warn

Audited by Gen Agent Trust Hub on Mar 18, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/with_server.py uses subprocess.Popen(shell=True) to execute server start commands provided as command-line arguments. This implementation is vulnerable to shell injection if the agent passes unvalidated or maliciously crafted strings to the script.
  • [PROMPT_INJECTION]: The skill possesses a significant indirect prompt injection attack surface. It is designed to navigate to external URLs and extract data such as page titles, headings, and link text using Playwright. This untrusted data is returned to the agent without sanitization or protective boundary markers.
  • Ingestion points: Untrusted data enters the agent context through scripts/playwright_runner.py and the browser_subagent tool which read web content.
  • Boundary markers: There are no delimiters or 'ignore' instructions wrapping the external content in the skill's workflows.
  • Capability inventory: The skill is explicitly granted Bash access in its metadata and includes scripts capable of spawning subprocesses.
  • Sanitization: The scripts do not perform any escaping or validation of the text retrieved from the target web pages before presenting it to the agent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 18, 2026, 07:46 AM
Security Audit — agent-trust-hub — webapp-testing