qa-persona-testing
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill interacts with external, untrusted web content through browser automation, which exposes an indirect prompt injection surface. A malicious application being tested could attempt to manipulate the agent's behavior. The skill proactively manages this via an 'anti-sycophancy contract' that requires the agent to adhere to specific behavioral budgets and report confusion in real-time. Ingestion points include accessibility tree snapshots and screenshots (documented in Phase 3 and references/browser-execution.md).
- [DYNAMIC_EXECUTION]: For headless testing and CI integration, the skill supports generating and executing Playwright scripts in Node.js or Python. While this involves dynamic code creation, it is a standard practice for the skill's primary purpose of automated regression testing (documented in references/browser-execution.md).
Audit Metadata