qa-persona-testing

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill interacts with external, untrusted web content through browser automation, which exposes an indirect prompt injection surface. A malicious application being tested could attempt to manipulate the agent's behavior. The skill proactively manages this via an 'anti-sycophancy contract' that requires the agent to adhere to specific behavioral budgets and report confusion in real-time. Ingestion points include accessibility tree snapshots and screenshots (documented in Phase 3 and references/browser-execution.md).
  • [DYNAMIC_EXECUTION]: For headless testing and CI integration, the skill supports generating and executing Playwright scripts in Node.js or Python. While this involves dynamic code creation, it is a standard practice for the skill's primary purpose of automated regression testing (documented in references/browser-execution.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:07 PM
Security Audit — agent-trust-hub — qa-persona-testing