antithesis-agent-browser

Pass

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the agent-browser CLI to automate interactions with the Antithesis platform, including opening URLs, waiting for network states, and downloading log files. These operations are restricted to the Antithesis domain and utilize isolated browser sessions to prevent cross-task data leakage.
  • [REMOTE_CODE_EXECUTION]: The skill injects a locally provided JavaScript runtime (assets/antithesis-agent-browser.js) into the browser context. This code is used to provide a structured API for the agent to query report data and discover runs. It does not perform any remote fetching of code or execute arbitrary user-supplied scripts.
  • [SAFE]: Security best practices are implemented for interactive authentication. The skill instructs the agent to verify the user's presence and obtain consent before launching a headed browser window for sign-in or 2FA, mitigating the risk of unexpected or deceptive UI interactions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 20, 2026, 10:41 PM
Security Audit — agent-trust-hub — antithesis-agent-browser