shoqai-automation
Pass
Audited by Gen Agent Trust Hub on Feb 16, 2026
Risk Level: LOWNO_CODEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [NO_CODE] (LOW): The core logic file automate-shoqai.js is referenced but not included in the provided files. Analysis is based on the functional description.
- [EXTERNAL_DOWNLOADS] (LOW): The skill downloads the Playwright browser binaries. Playwright is maintained by Microsoft, a trusted source, which minimizes the risk of this download.
- [COMMAND_EXECUTION] (LOW): The skill instructions involve executing local commands for setup and runtime, which is typical for browser automation tools.
- [PROMPT_INJECTION] (LOW): Category 8 (Indirect): The skill ingests data from external web pages (shoqai.com). Because its capabilities are limited to navigation and screenshots (display-only), the severity of this injection surface is low.
Audit Metadata