stably-verify

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the stably verify command-line interface to perform automated application testing. This involves running a CLI tool that controls a web browser to validate application features.
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the stably tool via npm install -g stably or to run it directly using npx stably. These are standard methods for utilizing Node.js packages from the official registry.
  • [INDIRECT_PROMPT_INJECTION]: The skill accepts a natural language description as an argument to define the expected behavior of the application being tested. This represents a vulnerability surface where data could influence agent actions.
  • Ingestion points: The description argument provided to the stably verify command in SKILL.md.
  • Boundary markers: None identified; the description is passed as a string literal.
  • Capability inventory: Command execution of the stably binary and subsequent automated browser actions (navigation, form interaction, clicking, and scrolling).
  • Sanitization: Not explicitly defined in the skill documentation; sanitization is assumed to be handled by the platform's backend processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 12:09 AM
Security Audit — agent-trust-hub — stably-verify