skills/mabhub/skills/webapp-testing/Gen Agent Trust Hub

webapp-testing

Pass

Audited by Gen Agent Trust Hub on Mar 31, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The helper script scripts/with_server.py utilizes subprocess.Popen with shell=True to manage the lifecycle of local web servers. This is used to support shell-specific features like command chaining (e.g., cd backend && python server.py). While functionally necessary for the skill's purpose, the use of shell=True is a known risk for command injection if untrusted arguments are processed.
  • [PROMPT_INJECTION]: The skill is vulnerable to Indirect Prompt Injection (Category 8) because it is designed to ingest and process data from external web pages.
  • Ingestion points: The agent retrieves untrusted data from web pages via Playwright methods such as page.content(), page.locator().all(), and console log capture (page.on('console', ...)).
  • Boundary markers: The SKILL.md file contains a dedicated security section ('Garde-fous de sécurité') with instructions to the agent, but it does not define technical delimiters to separate ingested web content from agent instructions.
  • Capability inventory: The agent has the capability to generate and execute Python scripts, run shell commands through the provided helper script, and write files to the /tmp directory.
  • Sanitization: The instructions recommend that the agent verify the content of generated scripts before execution, but no programmatic sanitization or filtering of the web-scraped content is implemented.
  • [COMMAND_EXECUTION]: The core functionality of the skill involves the agent generating and executing Python code. The instructions guide the agent to create Playwright scripts to interact with the DOM. While the skill includes guardrails (e.g., prohibiting the use of requests or urllib in these scripts), the execution of runtime-generated code remains a significant capability that must be monitored.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 31, 2026, 04:55 PM
Security Audit — agent-trust-hub — webapp-testing