{"data":{"skill":{"slug":"zhanlincui-webapp-testing","name":"webapp-testing","icon":"📦","repo":"https://github.com/ZhanlinCui/Ultimate-Agent-Skills-Collection/tree/main/webapp-testing","status":"approved","author":"ZhanlinCui","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"dc03fe7c-274a-4942-b130-a189aff68064","skill_id":"3760fc52-a467-48d9-ac1d-1f7dda0de51f","version":2,"content_hash":"771c5e9e2e77e464de1f9f776fc4bc37","risk_level":"high","is_blocked":false,"safe_to_publish":false,"analysis_status":"ok","agent_auto_install_policy":null,"manual_install_policy":null,"summary":"Static findings for weak cryptography are false positives; the cited lines contain description text and argparse setup, not cryptographic algorithms. The skill still has confirmed high-risk behavior because it encourages black-box script execution and includes a helper that runs user-supplied server commands through a shell.","remediation":[],"risk_factor_evidence":[{"factor":"scripts","evidence":[{"file":"scripts/with_server.py","line_end":1,"line_start":1}]},{"factor":"network","evidence":[{"file":"examples/console_logging.py","line_end":5,"line_start":5},{"file":"examples/element_discovery.py","line_end":10,"line_start":10},{"file":"SKILL.md","line_end":59,"line_start":59}]},{"factor":"filesystem","evidence":[{"file":"examples/console_logging.py","line_end":31,"line_start":31},{"file":"examples/element_discovery.py","line_end":37,"line_start":37},{"file":"examples/element_discovery.py","line_end":38,"line_start":38},{"file":"SKILL.md","line_end":69,"line_start":69}]},{"factor":"external_commands","evidence":[{"file":"scripts/with_server.py","line_end":74,"line_start":69},{"file":"scripts/with_server.py","line_end":88,"line_start":88}]}],"critical_findings":[],"high_findings":[{"title":"Prompt Injection Attempt Detected","locations":[{"file":"SKILL.md","line_end":14,"line_start":14},{"file":"SKILL.md","line_end":85,"line_start":85}],"confidence":0.88,"description":"SKILL.md instructs agents to avoid reading helper source before running it and to treat scripts as black boxes. This can suppress inspection of executable code before use.","confidence_reasoning":"The text directly tells the agent not to read source before executing helper scripts. It is suspicious in a marketplace skill because it can interfere with source inspection and safety review."},{"title":"User-Supplied Shell Command Execution","locations":[{"file":"scripts/with_server.py","line_end":74,"line_start":68}],"confidence":0.93,"description":"with_server.py passes the --server argument to subprocess.Popen with shell=True. A crafted server string can execute arbitrary shell operations in the caller environment.","confidence_reasoning":"The code explicitly uses shell=True with an argument supplied through the command line. The behavior is intentional, but it is still a clear arbitrary command execution surface."}],"medium_findings":[{"title":"Arbitrary Follow-Up Command Execution","locations":[{"file":"scripts/with_server.py","line_end":89,"line_start":86}],"confidence":0.8,"description":"with_server.py runs the remaining command-line arguments after servers are ready. This is expected for the tool, but it can execute unsafe commands if prompt input is untrusted.","confidence_reasoning":"The command is executed without shell=True, which reduces injection risk. It still runs arbitrary user-selected programs as part of normal operation."},{"title":"Browser Output Written to Local Filesystem","locations":[{"file":"examples/console_logging.py","line_end":31,"line_start":31},{"file":"examples/element_discovery.py","line_end":38,"line_start":37},{"file":"SKILL.md","line_end":69,"line_start":69}],"confidence":0.76,"description":"Example scripts write console logs and screenshots to local paths. This is useful for debugging but can store sensitive page content outside the project.","confidence_reasoning":"The writes are explicit and local, so this is not exfiltration. The risk is moderate because captured browser content can include private data."}],"low_findings":[{"title":"Hardcoded Localhost URLs Are Benign Examples","locations":[{"file":"examples/console_logging.py","line_end":5,"line_start":5},{"file":"examples/element_discovery.py","line_end":10,"line_start":10},{"file":"SKILL.md","line_end":59,"line_start":59}],"confidence":0.92,"description":"The detected URLs point to localhost and are used as example targets for local web testing. No external data exfiltration endpoint is present.","confidence_reasoning":"All cited URLs use localhost and match the stated purpose of testing local web applications. I did not find evidence of remote collection or transmission."},{"title":"Weak Cryptography Alerts Are False Positives","locations":[{"file":"SKILL.md","line_end":3,"line_start":3},{"file":"scripts/with_server.py","line_end":38,"line_start":36},{"file":"SKILL.md","line_end":88,"line_start":88}],"confidence":0.98,"description":"The cited lines contain descriptive metadata and argparse option definitions, not weak hashing or cryptographic operations. No evidence found for cryptographic misuse.","confidence_reasoning":"The cited lines were reviewed directly and contain no cryptographic API usage. This is a scanner pattern mismatch."}],"dangerous_patterns":[{"title":"subprocess.Popen with shell=True","locations":[{"file":"scripts/with_server.py","line_end":74,"line_start":68}],"confidence":0.93,"description":"The helper starts a server command through the shell, enabling shell metacharacter interpretation from the supplied command string.","confidence_reasoning":"The shell=True argument is visible in the subprocess.Popen call. This is a well-known command execution risk when command strings are not constrained."},{"title":"Instruction to Use Executable Scripts as Black Boxes","locations":[{"file":"SKILL.md","line_end":14,"line_start":14},{"file":"SKILL.md","line_end":85,"line_start":85}],"confidence":0.88,"description":"The skill text encourages direct execution of bundled scripts while discouraging source review. This raises supply-chain review risk for marketplace users.","confidence_reasoning":"The wording is explicit and directly affects how an AI agent should handle bundled executable code. It is not proof of malware, but it is a strong safety concern."}],"files_scanned":5,"total_lines":310,"audit_model":"codex","audited_at":"2026-07-01T02:48:32.188+00:00","created_at":"2026-07-01T04:01:08.253965+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"canonical install advisories are incomplete"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"high","confirmedFindingCount":1,"capabilityReviewCount":3,"needsReviewCount":0,"falsePositiveCount":2,"agentAutoInstallPolicy":null,"manualInstallPolicy":null,"artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}