storybook-play-functions
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill establishes a pattern where the agent interacts with UI elements based on labels and roles. This creates a surface for indirect prompt injection if the labels in the analyzed components are controlled by an untrusted party.\n
- Ingestion points: The skill relies on the agent reading component metadata and UI labels from the project workspace to generate tests.\n
- Boundary markers: There are no instructions for the agent to treat UI labels as untrusted data or use protective delimiters.\n
- Capability inventory: The skill utilizes Bash, Write, and Edit tools, which could be misused if the agent attempts to execute commands based on injected strings found in component roles.\n
- Sanitization: The provided templates do not include sanitization or validation for the element queries.
Audit Metadata