agentation-self-driving

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external websites using browser tools, which can lead to indirect prompt injection if a site contains hidden or adversarial instructions. Any instructions found on the target web page could potentially be executed by the agent due to its broad browser interaction capabilities.
  • Ingestion points: The skill uses agent-browser snapshot -i and agent-browser eval to read the structure and text content of a web page in SKILL.md.
  • Capability inventory: The skill possesses the capability to perform actions via agent-browser, including clicking, typing text (fill), and moving the mouse cursor, allowing it to act on instructions found on a page.
  • Boundary markers: The instructions do not provide specific delimiters or warnings to the agent to disregard instructions embedded within the target web page's content.
  • Sanitization: There is no evidence of sanitization or filtering of the web content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 09:54 AM
Security Audit — agent-trust-hub — agentation-self-driving