uat-coordinator
Pass
Audited by Gen Agent Trust Hub on Apr 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for the agent to perform automated testing using the Power Platform CLI (
pac test run) and browser automation through Playwright (Preview.PlaywrightAction()). These operations are consistent with the skill's defined role in software verification and utilize standard industry tools. - [PROMPT_INJECTION]: The skill facilitates the processing of external 'Acceptance Criteria' to generate UAT scripts and automated test plans, which creates an indirect prompt injection surface.
- Ingestion points: Acceptance Criteria provided as user input or project documentation.
- Boundary markers: No specific delimiters or safety instructions are defined to separate untrusted input from the agent's core instructions.
- Capability inventory: The skill utilizes system-level commands (Power Platform CLI) and browser automation capabilities (Playwright).
- Sanitization: The workflow does not include explicit validation or sanitization of the input data before it is processed by the agent.
Audit Metadata