selenium-expert
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to interact with external, potentially untrusted web pages via Selenium WebDriver. This creates an inherent surface for indirect prompt injection if the agent processes malicious instructions embedded in the HTML or UI of the sites being tested.
- Ingestion points: Browser interaction via
driver.get()and data extraction using methods likefind_element().textinreferences/EXAMPLES.md. - Boundary markers: The skill does not explicitly provide instructions or patterns for sanitizing page content or ignoring embedded instructions.
- Capability inventory: The skill allows file writing (
Write,Edit), shell command execution (Bash), and network operations via the Selenium WebDriver. - Sanitization: No explicit sanitization or filtering of external web content is demonstrated in the provided code examples.
- [DYNAMIC_EXECUTION]: The
BasePageclass inreferences/EXAMPLES.mdincludes anexecute_scriptmethod that wraps Selenium'sdriver.execute_script. This allows for the execution of arbitrary JavaScript within the browser context, which is a standard but powerful feature of WebDriver. - [EXTERNAL_DOWNLOADS]: The skill references several external resources for documentation and tooling, including
selenium.dev,applitools.com,aerokube.com, and repositories undergithub.com/SeleniumHQandgithub.com/zalando. These are well-known services and official repositories within the software testing ecosystem. - [COMMAND_EXECUTION]: The skill configuration in
SKILL.mdincludesBashin theallowed-toolssection. This capability is intended for tasks such as managing Selenium Grid containers or executing test suites but represents a significant permission level for the agent.
Audit Metadata