visual-debug
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references an installation script located at
https://raw.githubusercontent.com/voidmatcha/ui-clone-skills/main/install.sh. Per the author's instructions, this command is surfaced to the user for manual execution if dependencies are missing, rather than being executed automatically by the skill. - [COMMAND_EXECUTION]: Multiple scripts (e.g.,
ae-compare.sh,section-compare.sh,animation-spec-compare) usesubprocess.runor direct shell execution to invoke system utilities such asmagick,identify,ffmpeg,dssim, andagent-browser. These operations are fundamental to the skill's purpose of visual analysis. - [DYNAMIC_EXECUTION]: The suite dynamically generates and executes JavaScript snippets within browser sessions via
agent-browser --session eval. This is used to extract live metrics like computed styles, DOM nesting, and animation frame progress. The logic is encapsulated in library files likelib/enumerate-sections.jsandlib/extract-dom.js. - [INDIRECT_PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it ingests and processes untrusted data from external URLs during the verification process.
- Ingestion points:
ref-urlandimpl-urlparameters in scripts such aslive-parity-sweep.shandsection-compare.sh. - Boundary markers: Findings are typically output to structured JSON or markdown files (e.g.,
sections/result.json), which helps isolate external content from the agent's primary instruction stream. - Capability inventory: The skill can execute shell commands via
subprocessand perform network operations through the browser automation tool. - Sanitization: The skill performs normalization on text and CSS properties to facilitate comparison, though it does not explicitly filter for malicious payloads within the analyzed sites.
Audit Metadata