ghost-browser

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses subprocess.Popen in ghost_launch.py to launch Google Chrome with specific debugging arguments and a custom user data directory.
  • [COMMAND_EXECUTION]: ghost_launch.py executes pkill to forcefully close existing Google Chrome instances before relaunching.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to browse the live web and process page content using an LLM. It is vulnerable to instructions embedded in websites that might attempt to override the agent's safety rules, though it includes a 'SAFETY RULES' system message extension to mitigate this.
  • [DATA_EXPOSURE]: The skill explicitly copies real Chrome profile data (including login sessions and cookies) to a temporary directory to enable automation on logged-in accounts. While intended for its primary purpose, this involves handling sensitive session data.
  • [PRIVILEGE_ESCALATION]: The ghost_chrome.py script uses stealth JavaScript to bypass bot detection by overriding navigator.webdriver and other browser properties.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 08:27 PM