qa
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted data from external web applications, creating a surface for potential indirect prompt injection attacks. Ingestion points: The agent visits user-provided target URLs and parses page HTML, navigation links, and console logs as described in
SKILL.md. Boundary markers: No specific delimiters or isolation instructions are used to distinguish untrusted web content from the agent's core instructions. Capability inventory: The agent has the ability to interact with web pages (fill, click), create directories, and write local files (reports, screenshots, baseline JSON) as seen in the workflow sections ofSKILL.md. Sanitization: The instructions include a specific rule to redact passwords from repro steps before including them in any reports.
Audit Metadata