agent-browser
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process content from external websites, creating a significant attack surface for indirect prompt injection.
- Ingestion points: Untrusted data enters the agent context via
agent-browser snapshot(accessibility/DOM tree),agent-browser get text/html(page content), andagent-browser console/errors(browser execution logs). - Boundary markers: The instructions do not provide delimiters or warnings to prevent the agent from following instructions embedded in the web content it processes.
- Capability inventory: The agent possesses powerful tools that could be abused if it follows malicious instructions from a webpage, including arbitrary JavaScript execution (
eval), session data access (cookies,storage), and the ability to write files (screenshot,pdf,record,state save) to the local disk. - Sanitization: No mechanisms are described for validating or sanitizing the content retrieved from the browser.
- [DYNAMIC_EXECUTION]: The skill exposes functionality for executing arbitrary JavaScript within the browser's context.
agent-browser evalexecutes a provided JavaScript string.agent-browser wait --fnevaluates a JavaScript condition.- [COMMAND_EXECUTION]: The skill facilitates system interaction through a specialized CLI via the
Bashtool, enabling file system operations such asupload,screenshot, and sessionstate save/load.
Audit Metadata