webapp-testing

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/with_server.py executes arbitrary shell commands provided via the --server and command arguments using subprocess.Popen with shell=True. This allows for shell features like command chaining but increases the risk of command injection. The skill instructions explicitly advise the agent to treat this script as a black box and avoid reading its source code, which reduces oversight of these execution primitives.
  • [DYNAMIC_EXECUTION]: The skill's primary workflow involves the agent dynamically generating and executing Python scripts (using Playwright) to interact with web applications. While intended, this represents a high-capability execution surface.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides patterns for the agent to inspect rendered DOM content and page text (via page.content() and page.locator().all()). This creates a surface for indirect prompt injection if the web application being tested contains malicious instructions designed to influence the agent's behavior.
  • Ingestion points: Web page content, DOM structure, and text values captured in examples/element_discovery.py, examples/static_html_automation.py, and the workflows recommended in SKILL.md.
  • Boundary markers: Absent; there are no instructions for the agent to use delimiters or ignore embedded instructions when processing content from the web applications.
  • Capability inventory: The agent has the ability to execute shell commands (via scripts/with_server.py), write files (screenshots and logs), and perform network operations via Playwright.
  • Sanitization: No explicit sanitization or filtering of the retrieved web page content is implemented before the agent processes it for element discovery and interaction.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 11:01 PM
Security Audit — agent-trust-hub — webapp-testing