stably-verify
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
stably verifycommand-line interface to perform automated application testing. This involves running a CLI tool that controls a web browser to validate application features. - [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the
stablytool vianpm install -g stablyor to run it directly usingnpx stably. These are standard methods for utilizing Node.js packages from the official registry. - [INDIRECT_PROMPT_INJECTION]: The skill accepts a natural language description as an argument to define the expected behavior of the application being tested. This represents a vulnerability surface where data could influence agent actions.
- Ingestion points: The
descriptionargument provided to thestably verifycommand inSKILL.md. - Boundary markers: None identified; the description is passed as a string literal.
- Capability inventory: Command execution of the
stablybinary and subsequent automated browser actions (navigation, form interaction, clicking, and scrolling). - Sanitization: Not explicitly defined in the skill documentation; sanitization is assumed to be handled by the platform's backend processing.
Audit Metadata