skills/jayden-dang/skills/validate-ui/Gen Agent Trust Hub

validate-ui

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill identifies and executes shell commands to start the application and run Playwright end-to-end tests.
  • [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill automatically installs the @playwright/test package if a testing harness is not detected in the repository.
  • [DYNAMIC_EXECUTION]: The skill generates Playwright test scripts at runtime based on the requirement ledger and then executes them using the Playwright CLI.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes project documentation and a requirements ledger to generate executable scripts, which presents a surface for indirect prompt injection. • Ingestion points: docs/agents/project.md, docs/standards/ui.md, and the provided acceptance ledger. • Boundary markers: No explicit delimiters or instructions to isolate external content from instructions are present. • Capability inventory: Shell command execution, package installation, and file system write access for updating documentation and committing tests. • Sanitization: No validation or sanitization of the input data before it is used to generate executable test scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 03:21 PM
Security Audit — agent-trust-hub — validate-ui