qa-expert
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides automated testing frameworks that ingest content from external, untrusted sources such as web pages and API endpoints.
- Ingestion points: Data enters the agent context through Selenium's
get_textmethod in theLoginPageclass and JSON response parsing in theAPITestClientclass. - Boundary markers: The code snippets do not include explicit delimiters or instructions to ignore potential commands embedded in the data retrieved from external sites.
- Capability inventory: The skill is authorized to use
Bashfor Python execution, as well asWriteandEdittools, allowing it to perform network operations and file modifications. - Sanitization: The provided templates do not demonstrate sanitization or validation of external content before processing.
- [DATA_EXFILTRATION]: The skill performs network operations using the
requestslibrary and Selenium WebDriver. - Network operations: The
APITestClientandTestRunnerclasses initiate network requests to dynamic URLs provided during execution. While the provided examples use standard placeholders likeexample.com, the framework allows interactions with any user-defined or externally-sourced domain.
Audit Metadata