user-behavior-qa

Pass

Audited by Gen Agent Trust Hub on Oct 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from the web applications it tests, which could potentially contain malicious instructions.
  • Ingestion points: The agent reads rendered page content, UI labels, and browser console errors from external applications being tested as described in SKILL.md.
  • Boundary markers: Instructions explicitly define the browser as the product boundary and caution against inspecting internal implementation details unless scoped by the user.
  • Capability inventory: The skill utilizes browser automation tools (like Playwright) to navigate pages, interact with UI controls, and create or delete test data in development environments.
  • Sanitization: No specific filtering or escaping mechanisms are described for processing the external web content before it is interpreted by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 9, 2026, 10:30 AM