multi-user-workflow-generator
Pass
Audited by Gen Agent Trust Hub on Oct 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted codebase content and live application UI snapshots, creating a surface for indirect prompt injection. Malicious data in these sources could influence the agent's logic or output.
- Ingestion points: Project files (via Read, Grep, Glob) and live app state (via Playwright snapshots).
- Boundary markers: No explicit delimiters are specified for separating untrusted content from the system prompt.
- Capability inventory: The skill can execute shell commands via playwright-cli and write files to the project directory.
- Sanitization: Ingested content is not filtered or sanitized.
- [COMMAND_EXECUTION]: The skill constructs and executes playwright-cli commands through the Bash tool to perform browser automation. These commands are generated dynamically based on the agent's interpretation of the application and are subject to user confirmation before execution.
Audit Metadata