executar-qa

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted data from project documentation and live application content to determine its browser interactions. Ingestion points: PRD (./tasks/prd-[feature-slug]/prd.md), Tech Spec (./tasks/prd-[feature-slug]/techspec.md), and application state via browser_snapshot. Boundary markers: No delimiters or isolation instructions are present to prevent the agent from obeying instructions embedded within the ingested files. Capability inventory: The skill has access to Playwright MCP tools such as browser_click, browser_type, and browser_navigate, allowing it to perform actions in a browser environment. Sanitization: There is no evidence of sanitization or filtering of external content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 03:23 AM
Security Audit — agent-trust-hub — executar-qa