skills/simota/agent-skills/voyager/Gen Agent Trust Hub

voyager

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONPRIVILEGE_ESCALATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill describes workflows involving AI agents (e.g., Playwright Test Agents) that explore application UI and accessibility trees to generate tests. This architectural design creates a surface where the generated code could be influenced by untrusted content within the application under test.
  • Ingestion points: UI exploration by agents like the Planner and Generator (documented in reference/ai-powered-e2e-testing.md).
  • Boundary markers: The documentation does not specify explicit boundary markers for these automated interactions.
  • Capability inventory: The skill involves file-system writes for test files and command execution for running test suites.
  • Sanitization: Standard sanitization for application-sourced data is not explicitly detailed in the provided reference materials.
  • [COMMAND_EXECUTION]: The skill provides standard shell commands for package management, test execution, and CI operations (e.g., npx playwright test, npm install). It also references the use of Node.js child_process for local automation tasks, which is standard for developer tooling.
  • [EXTERNAL_DOWNLOADS]: The skill directs users to install well-known testing frameworks and utilities from official registries (NPM) and trusted repositories (GitHub), such as those from Microsoft, Cypress, and the Appium project. These downloads are from established organizations and are standard for the testing ecosystem.
  • [PRIVILEGE_ESCALATION]: The CI/CD integration guides include common administrative commands like sudo xcode-select for managing system build tools, which is a standard requirement for iOS development and CI environments.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 01:49 PM
Security Audit — agent-trust-hub — voyager