selenium-expert

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to interact with external, potentially untrusted web pages via Selenium WebDriver. This creates an inherent surface for indirect prompt injection if the agent processes malicious instructions embedded in the HTML or UI of the sites being tested.
  • Ingestion points: Browser interaction via driver.get() and data extraction using methods like find_element().text in references/EXAMPLES.md.
  • Boundary markers: The skill does not explicitly provide instructions or patterns for sanitizing page content or ignoring embedded instructions.
  • Capability inventory: The skill allows file writing (Write, Edit), shell command execution (Bash), and network operations via the Selenium WebDriver.
  • Sanitization: No explicit sanitization or filtering of external web content is demonstrated in the provided code examples.
  • [DYNAMIC_EXECUTION]: The BasePage class in references/EXAMPLES.md includes an execute_script method that wraps Selenium's driver.execute_script. This allows for the execution of arbitrary JavaScript within the browser context, which is a standard but powerful feature of WebDriver.
  • [EXTERNAL_DOWNLOADS]: The skill references several external resources for documentation and tooling, including selenium.dev, applitools.com, aerokube.com, and repositories under github.com/SeleniumHQ and github.com/zalando. These are well-known services and official repositories within the software testing ecosystem.
  • [COMMAND_EXECUTION]: The skill configuration in SKILL.md includes Bash in the allowed-tools section. This capability is intended for tasks such as managing Selenium Grid containers or executing test suites but represents a significant permission level for the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 05:13 AM
Security Audit — agent-trust-hub — selenium-expert