qa
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to systematically explore and report on web applications, which involves processing untrusted external data.
- Ingestion points: The agent ingests data from target URLs, feature branch diffs (via
origin/main), and page content accessed through@Browser,@Chrome, or Computer Use tools. - Boundary markers: The instructions lack explicit boundary markers or instructions to treat page content as untrusted data, increasing the risk that the agent might follow instructions embedded in the HTML or console logs of the site being tested.
- Capability inventory: The skill has the capability to browse the web, execute repo-local tests, and inspect git diffs. A combined attack could use a malicious website to trigger unwanted local repository operations or exfiltrate branch data if the agent interprets site content as commands.
- Sanitization: No sanitization or filtering of external application content is specified in the workflow or templates.
Audit Metadata