browser-automation
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted HTML files to generate automation scripts, creating an attack surface where malicious input could influence the generated code. A crafted HTML file could use field names or URLs containing quote marks and Python code to inject instructions into the resulting output script.\n
- Ingestion points: The
scripts/form_automation_builder.pyscript reads HTML content from user-provided files via the--html-fileargument.\n - Boundary markers: There are no markers or instructions in the code generation logic to delimit or ignore potentially malicious patterns in the input HTML.\n
- Capability inventory: Both
scripts/form_automation_builder.pyandscripts/scraping_toolkit.pyutilize file-writing capabilities (Path.write_text) to save generated Python scripts to the filesystem.\n - Sanitization: The generator logic lacks sanitization for HTML attributes (e.g., input names, form actions) before interpolating them into f-string templates used for code generation.\n- [DYNAMIC_EXECUTION]: The skill performs runtime generation of executable Python scripts from predefined templates.\n
- Evidence: The tools
scripts/form_automation_builder.pyandscripts/scraping_toolkit.pyuse string concatenation and text wrapping to assemble complete Python scripts that use therequestslibrary, then write these scripts to the local disk for execution.
Audit Metadata