visual-qa-rubric
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external web content and DOM snapshots to perform audits, which establishes an attack surface where external content could attempt to influence agent behavior. However, this is inherent to the skill's purpose as a visual QA tool.
- Ingestion points: The Browser/Screenshot Workflow section in SKILL.md describes ingesting target page content and DOM snapshots.
- Capability inventory: The skill leverages browser tools for navigation, screenshotting, and analyzing network/console logs.
- Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands within the audited content.
- Sanitization: No explicit sanitization or filtering of the external page content is performed by the skill logic.
Audit Metadata