browser-preview
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute specific shell commands including
cat,curl, andfind. These are used to inspect internal registry files (/data/previews.json), verify local port availability onlocalhostfor diagnostic purposes, and scan the workspace to identify project structures. - [INDIRECT_PROMPT_INJECTION]: The diagnostic workflow involves reading and processing data from internal registry files and project-specific files (such as
package.jsonorindex.html). This content is used to populate parameters for thepreview_servetool. While this creates an ingestion surface for potentially untrusted workspace data, it is a functional requirement for the skill's primary purpose of managing local development previews. - Ingestion points: Files at
/data/previews.json,/data/preview_history.json, and project metadata files within/data/workspace. - Boundary markers: None explicitly defined in the instructions for the registry data.
- Capability inventory: Uses
catandfindfor file access, andpreview_servefor executing build/start commands. - Sanitization: The skill assumes the validity of commands found in the registry or history, relying on the underlying platform's tool safety for execution.
Audit Metadata