break-fix
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill is designed to discover and execute existing test scripts and configuration commands within a target repository (e.g., Playwright, Cypress, Puppeteer) as part of its bug-hunting and regression verification workflow, as described in
references/e2e-harnesses.mdandSKILL.md. - [INDIRECT_PROMPT_INJECTION]: The skill interacts with external applications to perform exploratory testing, which introduces a surface for indirect prompt injection where malicious instructions could be embedded in the data processed by the agent.
- Ingestion points: The agent ingests data from application user interfaces, API responses, server logs, and project source code during its diagnostic and hunting phases.
- Boundary markers: The instructions include verbal constraints to keep tests contained and avoid production environments, but lack technical delimiters or explicit instructions to ignore embedded commands in the ingested data.
- Capability inventory: The skill has capabilities to modify the source code ("fix mode") and execute shell commands to run test harnesses.
- Sanitization: There are no documented procedures for sanitizing or validating external content before it is processed by the agent.
Audit Metadata