adversarial-ux-test
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill interacts with external websites and project documentation (ingestion points) to conduct testing. Because it lacks explicit boundary markers or content sanitization, it is theoretically susceptible to instructions embedded within the target website's text or metadata that could influence the agent's persona or reporting. However, the risk is mitigated by the structured multi-step process defined in the instructions.
- [COMMAND_EXECUTION]: The skill uses browser tools to navigate URLs, check JavaScript console logs, and take screenshots (capability inventory). It also includes instructions to generate issue tickets based on findings. These operations are within the scope of the stated purpose for UX testing and triage.
Audit Metadata