scoutqa-test
Pass
Audited by Gen Agent Trust Hub on Jul 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill relies on the
@scoutqa/clipackage from the public NPM registry for its core functionality. - Evidence: The troubleshooting section in
SKILL.mdprovides the installation commandnpm i -g @scoutqa/cli@latest. - [COMMAND_EXECUTION]: The skill uses the
scoutqacommand-line interface to interact with a remote testing service. - Evidence: The testing workflow utilizes commands like
scoutqa --url "https://example.com" --prompt "..."andscoutqa send-message --execution-id .... - [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it processes untrusted user data (URLs and test instructions) which are then interpreted by the remote ScoutQA agent.
- Ingestion points: External data enters through the
--urland--promptparameters inSKILL.md. - Boundary markers: No specific delimiters or boundary warnings are used when interpolating user-provided instructions into the command string.
- Capability inventory: The skill possesses the capability to execute shell commands via the
Bashtool and send arbitrary natural language prompts to a remote autonomous testing agent. - Sanitization: There is no evidence of input validation or escaping for the user-supplied strings before they are passed to the CLI.
Audit Metadata