friction
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external content, such as web applications and source code, during the audit workflow. An attacker-controlled target could include hidden instructions to manipulate the agent's audit findings or subsequent code fixes. 1. Ingestion points: Data is ingested during the novice/expert walks and the automated accessibility pass using browser tools (specified in SKILL.md, Workflow steps 2 and 4). 2. Boundary markers: There are no explicit instructions or delimiters to isolate processed application data from the agent's primary instructions. 3. Capability inventory: The agent is instructed to directly modify code to fix identified blockers and major issues, and it utilizes browser automation tools. 4. Sanitization: No sanitization, validation, or filtering mechanisms are defined for the external content processed during the audit.
Audit Metadata