agent-browser

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process content from external websites, creating a significant attack surface for indirect prompt injection.
  • Ingestion points: Untrusted data enters the agent context via agent-browser snapshot (accessibility/DOM tree), agent-browser get text/html (page content), and agent-browser console/errors (browser execution logs).
  • Boundary markers: The instructions do not provide delimiters or warnings to prevent the agent from following instructions embedded in the web content it processes.
  • Capability inventory: The agent possesses powerful tools that could be abused if it follows malicious instructions from a webpage, including arbitrary JavaScript execution (eval), session data access (cookies, storage), and the ability to write files (screenshot, pdf, record, state save) to the local disk.
  • Sanitization: No mechanisms are described for validating or sanitizing the content retrieved from the browser.
  • [DYNAMIC_EXECUTION]: The skill exposes functionality for executing arbitrary JavaScript within the browser's context.
  • agent-browser eval executes a provided JavaScript string.
  • agent-browser wait --fn evaluates a JavaScript condition.
  • [COMMAND_EXECUTION]: The skill facilitates system interaction through a specialized CLI via the Bash tool, enabling file system operations such as upload, screenshot, and session state save/load.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 09:02 PM
Security Audit — agent-trust-hub — agent-browser