webapp-testing
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/with_server.pyutilizessubprocess.Popenwithshell=Trueto execute server startup commands (e.g.,npm run dev) andsubprocess.runto execute automation scripts. This pattern is necessary for shell-based task chaining required in local development environments. - [PROMPT_INJECTION]: The skill facilitates indirect prompt injection by design, as it ingests and processes content from potentially untrusted web applications.
- Ingestion points: The agent is instructed to read web page content via
page.content(), examine DOM attributes inexamples/element_discovery.py, and capture browser console logs inexamples/console_logging.py. - Boundary markers: Absent. The instructions do not provide specific delimiters or warnings to separate untrusted web content from the agent's primary instructions.
- Capability inventory: The skill environment allows for shell command execution via
scripts/with_server.py, file system writes for logging and screenshots, and network navigation through Playwright. - Sanitization: None. Data retrieved from the browser is used directly to identify selectors and verify application behavior.
- [DATA_EXFILTRATION]: Several example scripts (
examples/console_logging.py,examples/static_html_automation.py) perform local data exposure by writing screenshots and log files to shared directories such as/tmp/and/mnt/user-data/outputs/.
Audit Metadata