h5p-verify
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads and executes the
@missing-elements/h5p-verifypackage andplaywrightvianpx. These resources are owned by the skill's author or are well-known browser automation tools, used here for their intended purpose of package verification. - [COMMAND_EXECUTION]: The skill requires the execution of CLI commands to run the verification tool and install browser dependencies. The commands are standard for this utility's use case.
- [INDIRECT_PROMPT_INJECTION]: The skill processes external
.h5parchive files, which contain content that could potentially include instructions targeting the agent or the rendering environment. - Ingestion points: Reads and executes content from the
package.h5pfile provided as input. - Boundary markers: None explicitly defined in the prompt instructions.
- Capability inventory: The tool executes a headless Chromium browser to render the package, generates a JSON report, and saves a screenshot to the local filesystem.
- Sanitization: The skill instructions do not specify sanitization steps, relying on the underlying tool's handling of the H5P runtime.
Audit Metadata