momentic-result-classification
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: Indirect Prompt Injection Surface
- Ingestion points: The skill processes external, untrusted application data from test execution outputs in
SKILL.md, such as DOM snapshots (<snapshotId>.html), browser console outputs (console.json), and network log files (har-entries.log). - Boundary markers: There are no explicit instructions or delimiters configured to separate untrusted text or tell the LLM to ignore embedded commands within the analyzed web content.
- Capability inventory: The skill is configured with specific diagnostic MCP tools (
momentic_get_run,momentic_list_runs,momentic_get_step_result,momentic_get_test_steps_for_run,momentic_submit_result_classification) to fetch and record results. It lacks arbitrary command execution or unwhitelisted network exfiltration capabilities. - Sanitization: No sanitization, escaping, or strict schema validation is applied to raw DOM strings or log messages prior to processing.
Audit Metadata