agent-browser

Warn

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: MEDIUMPROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it instructs the agent to process content from untrusted external websites through commands like snapshot and get text.
  • Ingestion points: Commands such as agent-browser snapshot, agent-browser get text @e1, and agent-browser get html @e1 bring external data into the agent's context.
  • Boundary markers: There are no instructions or delimiters defining how the agent should distinguish between web content and its primary instructions.
  • Capability inventory: The agent can use powerful tools like eval, cookies, storage, and network which could be abused if the agent is manipulated.
  • Sanitization: The skill lacks mechanisms to sanitize or filter web content before the agent processes it.
  • [DATA_EXFILTRATION]: The tool enables the extraction of sensitive information from both the browser and the host system.
  • Browser Data: Commands like agent-browser cookies and agent-browser storage local provide direct access to authentication session identifiers and local storage data.
  • System Files: The open command explicitly supports the file:// protocol, which can be used to read local system files (e.g., /etc/passwd or SSH keys) if the browser environment allows it.
  • Session Persistence: Instructions for saving and loading browser state (state save/load) to local files like auth.json could lead to sensitive authentication tokens being stored in insecure local files.
  • [COMMAND_EXECUTION]: The skill allows for dynamic execution within the browser and configuration of the browser binary itself.
  • JavaScript Execution: The eval command allows the agent to execute arbitrary JavaScript code within the current page context.
  • Custom Executables: The --executable-path flag and the AGENT_BROWSER_EXECUTABLE_PATH environment variable allow the execution of a custom binary, which could be a malicious file instead of a legitimate browser.
Audit Metadata
Risk Level
MEDIUM
Analyzed
May 14, 2026, 03:02 AM
Security Audit — agent-trust-hub — agent-browser