qa-expert

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides automated testing frameworks that ingest content from external, untrusted sources such as web pages and API endpoints.
  • Ingestion points: Data enters the agent context through Selenium's get_text method in the LoginPage class and JSON response parsing in the APITestClient class.
  • Boundary markers: The code snippets do not include explicit delimiters or instructions to ignore potential commands embedded in the data retrieved from external sites.
  • Capability inventory: The skill is authorized to use Bash for Python execution, as well as Write and Edit tools, allowing it to perform network operations and file modifications.
  • Sanitization: The provided templates do not demonstrate sanitization or validation of external content before processing.
  • [DATA_EXFILTRATION]: The skill performs network operations using the requests library and Selenium WebDriver.
  • Network operations: The APITestClient and TestRunner classes initiate network requests to dynamic URLs provided during execution. While the provided examples use standard placeholders like example.com, the framework allows interactions with any user-defined or externally-sourced domain.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 06:42 PM
Security Audit — agent-trust-hub — qa-expert