ghost-browser
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
subprocess.Popeninghost_launch.pyto launch Google Chrome with specific debugging arguments and a custom user data directory. - [COMMAND_EXECUTION]:
ghost_launch.pyexecutespkillto forcefully close existing Google Chrome instances before relaunching. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to browse the live web and process page content using an LLM. It is vulnerable to instructions embedded in websites that might attempt to override the agent's safety rules, though it includes a 'SAFETY RULES' system message extension to mitigate this.
- [DATA_EXPOSURE]: The skill explicitly copies real Chrome profile data (including login sessions and cookies) to a temporary directory to enable automation on logged-in accounts. While intended for its primary purpose, this involves handling sensitive session data.
- [PRIVILEGE_ESCALATION]: The
ghost_chrome.pyscript uses stealth JavaScript to bypass bot detection by overridingnavigator.webdriverand other browser properties.
Audit Metadata