webapp-testing

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/with_server.py uses subprocess.Popen with shell=True to execute commands provided via the --server argument. This is designed to support complex shell operations (like cd backend && npm start), but it means any command passed to this argument is executed directly by the system shell.
  • [COMMAND_EXECUTION]: The skill executes a secondary user-provided command after the servers are ready using subprocess.run(args.command). This allows the agent to execute arbitrary scripts or binaries on the host system as part of the testing workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 02:09 AM