auth-flow-audit
Pass
Audited by Gen Agent Trust Hub on Jul 6, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill uses the Playwright MCP to inspect website metadata, headers, and DOM structures. All operations are read-only and the instructions explicitly prohibit attempting actual logins or credential stuffing.
- [SAFE]: The skill references 'helpmetest.com', which is the official domain of the skill author 'help-me-test', representing a standard vendor resource.
- [SAFE]: While the skill ingests untrusted data from external websites during an audit (Indirect Prompt Injection surface), this is necessary for its primary function. The logic is focused on structured property checks (e.g., checking for the 'secure' flag on cookies) rather than executing instructions found within the site content.
Audit Metadata