playground-website-debugging
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions to manage the development environment using shell commands. This includes terminating processes bound to specific ports (5400, 5263, 6400) using
lsofandxargs kill, and starting the development server withnpm run dev. These commands are standard for the intended debugging workflow but involve direct process manipulation. - [INDIRECT_PROMPT_INJECTION]: The skill facilitates interaction with a dynamic web environment (WordPress Playground) using browser automation tools. By navigating to arbitrary paths and executing JavaScript within the browser context via
browser_run_code, the agent is exposed to external content that could potentially contain instructions aimed at influencing its behavior. - Ingestion points: Browser navigation via
browser_navigateandbrowser_typefor URL paths as described inSKILL.md. - Boundary markers: No specific delimiters or warnings to ignore instructions embedded in the website content are present.
- Capability inventory: Execution of shell commands (bash), file system writes (logs), and browser-side script execution (
browser_run_code) as seen inSKILL.md. - Sanitization: No sanitization or filtering of the web content or URL paths is implemented before processing.
Audit Metadata