playground-website-debugging

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions to manage the development environment using shell commands. This includes terminating processes bound to specific ports (5400, 5263, 6400) using lsof and xargs kill, and starting the development server with npm run dev. These commands are standard for the intended debugging workflow but involve direct process manipulation.
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates interaction with a dynamic web environment (WordPress Playground) using browser automation tools. By navigating to arbitrary paths and executing JavaScript within the browser context via browser_run_code, the agent is exposed to external content that could potentially contain instructions aimed at influencing its behavior.
  • Ingestion points: Browser navigation via browser_navigate and browser_type for URL paths as described in SKILL.md.
  • Boundary markers: No specific delimiters or warnings to ignore instructions embedded in the website content are present.
  • Capability inventory: Execution of shell commands (bash), file system writes (logs), and browser-side script execution (browser_run_code) as seen in SKILL.md.
  • Sanitization: No sanitization or filtering of the web content or URL paths is implemented before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 09:52 AM
Security Audit — agent-trust-hub — playground-website-debugging