mapping-webapp

Pass

Audited by Gen Agent Trust Hub on May 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill interacts with an external utility called webctl using the subprocess module. These calls are used to automate browser navigation, take screenshots, and capture accessibility trees for visual verification. The implementation uses list-based command arguments, which prevents shell injection vulnerabilities.
  • [EXTERNAL_DOWNLOADS]: The skill performs legitimate network operations to communicate with the Anthropic API and optionally Cloudflare AI Gateway for processing application data. These operations target established, well-known service endpoints and are essential for the skill's primary functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
May 7, 2026, 04:35 AM