webapp-testing
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/with_server.pyexecutes arbitrary shell commands provided via the--serverandcommandarguments usingsubprocess.Popenwithshell=True. This allows for shell features like command chaining but increases the risk of command injection. The skill instructions explicitly advise the agent to treat this script as a black box and avoid reading its source code, which reduces oversight of these execution primitives. - [DYNAMIC_EXECUTION]: The skill's primary workflow involves the agent dynamically generating and executing Python scripts (using Playwright) to interact with web applications. While intended, this represents a high-capability execution surface.
- [INDIRECT_PROMPT_INJECTION]: The skill provides patterns for the agent to inspect rendered DOM content and page text (via
page.content()andpage.locator().all()). This creates a surface for indirect prompt injection if the web application being tested contains malicious instructions designed to influence the agent's behavior. - Ingestion points: Web page content, DOM structure, and text values captured in
examples/element_discovery.py,examples/static_html_automation.py, and the workflows recommended inSKILL.md. - Boundary markers: Absent; there are no instructions for the agent to use delimiters or ignore embedded instructions when processing content from the web applications.
- Capability inventory: The agent has the ability to execute shell commands (via
scripts/with_server.py), write files (screenshots and logs), and perform network operations via Playwright. - Sanitization: No explicit sanitization or filtering of the retrieved web page content is implemented before the agent processes it for element discovery and interaction.
Audit Metadata