uat-nonit-testcase

Fail

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: HIGHCOMMAND_EXECUTIONCREDENTIALS_UNSAFEDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill implements dynamic context injection using the ! vercel deploy syntax, which can lead to the automated execution of shell commands and unauthorized deployment of local project files to the cloud when the skill is loaded.- [CREDENTIALS_UNSAFE]: The instructions mandate bypassing corporate Single Sign-On (SSO) and Microsoft authentication by manually injecting session cookies and access tokens into automated browser environments via Playwright.- [DATA_EXFILTRATION]: The skill facilitates the movement of sensitive internal data, including application screenshots and backend configuration constants, to public hosting infrastructure (Vercel).- [COMMAND_EXECUTION]: The agent is instructed to use automated browsing tools to probe internal network routes and API endpoints, extracting business logic and configuration values that may reside behind protected environments.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 14, 2026, 06:25 AM
Security Audit — agent-trust-hub — uat-nonit-testcase