webmcp-testing

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to perform multiple web searches to fetch live documentation and testing guidance. This process ingests content from external web sources into the agent's context, which represents a potential attack surface for indirect prompt injection.
  • Ingestion points: Web search queries targeting 'webmcp testing tools', 'Chrome EPP testing instructions', and 'mcp-b testing utilities' in the 'Before writing code' section.
  • Boundary markers: Absent. The instructions do not specify the use of delimiters or 'ignore embedded instructions' warnings when processing retrieved documentation.
  • Capability inventory: The skill is configured with broad capabilities including Write, Edit, Bash, and WebFetch tools, which could be exploited if an injection in the search results is successful.
  • Sanitization: Absent. There are no instructions for the agent to sanitize or validate the content retrieved from search results before using it to guide code generation or testing actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:33 PM