webapp-testing

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/with_server.py utilizes subprocess.Popen with shell=True to execute server startup commands (e.g., npm run dev) and subprocess.run to execute automation scripts. This pattern is necessary for shell-based task chaining required in local development environments.
  • [PROMPT_INJECTION]: The skill facilitates indirect prompt injection by design, as it ingests and processes content from potentially untrusted web applications.
  • Ingestion points: The agent is instructed to read web page content via page.content(), examine DOM attributes in examples/element_discovery.py, and capture browser console logs in examples/console_logging.py.
  • Boundary markers: Absent. The instructions do not provide specific delimiters or warnings to separate untrusted web content from the agent's primary instructions.
  • Capability inventory: The skill environment allows for shell command execution via scripts/with_server.py, file system writes for logging and screenshots, and network navigation through Playwright.
  • Sanitization: None. Data retrieved from the browser is used directly to identify selectors and verify application behavior.
  • [DATA_EXFILTRATION]: Several example scripts (examples/console_logging.py, examples/static_html_automation.py) perform local data exposure by writing screenshots and log files to shared directories such as /tmp/ and /mnt/user-data/outputs/.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 09:40 PM
Security Audit — agent-trust-hub — webapp-testing