webapp-testing
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/with_server.pyusessubprocess.Popenwithshell=Trueto execute commands provided via the--serverargument. This is designed to support complex shell operations (likecd backend && npm start), but it means any command passed to this argument is executed directly by the system shell. - [COMMAND_EXECUTION]: The skill executes a secondary user-provided command after the servers are ready using
subprocess.run(args.command). This allows the agent to execute arbitrary scripts or binaries on the host system as part of the testing workflow.
Audit Metadata