agentation-self-driving
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external websites using browser tools, which can lead to indirect prompt injection if a site contains hidden or adversarial instructions. Any instructions found on the target web page could potentially be executed by the agent due to its broad browser interaction capabilities.
- Ingestion points: The skill uses
agent-browser snapshot -iandagent-browser evalto read the structure and text content of a web page inSKILL.md. - Capability inventory: The skill possesses the capability to perform actions via
agent-browser, including clicking, typing text (fill), and moving the mouse cursor, allowing it to act on instructions found on a page. - Boundary markers: The instructions do not provide specific delimiters or warnings to the agent to disregard instructions embedded within the target web page's content.
- Sanitization: There is no evidence of sanitization or filtering of the web content before it is processed by the agent.
Audit Metadata