control-ui
Pass
Audited by Gen Agent Trust Hub on May 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides templates for generating and running browser automation scripts using Playwright to interact with local applications.
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection by processing data from application UIs and logs. Ingestion points: SKILL.md (ingesting page content, titles, URLs, and console logs via Playwright). Boundary markers: Absent in the script templates. Capability inventory: SKILL.md (browser control actions, file system writes for screenshots, and network operations). Sanitization: Absent; no verification of ingested UI content is performed.
Audit Metadata