browser-automation

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted HTML files to generate automation scripts, creating an attack surface where malicious input could influence the generated code. A crafted HTML file could use field names or URLs containing quote marks and Python code to inject instructions into the resulting output script.\n
  • Ingestion points: The scripts/form_automation_builder.py script reads HTML content from user-provided files via the --html-file argument.\n
  • Boundary markers: There are no markers or instructions in the code generation logic to delimit or ignore potentially malicious patterns in the input HTML.\n
  • Capability inventory: Both scripts/form_automation_builder.py and scripts/scraping_toolkit.py utilize file-writing capabilities (Path.write_text) to save generated Python scripts to the filesystem.\n
  • Sanitization: The generator logic lacks sanitization for HTML attributes (e.g., input names, form actions) before interpolating them into f-string templates used for code generation.\n- [DYNAMIC_EXECUTION]: The skill performs runtime generation of executable Python scripts from predefined templates.\n
  • Evidence: The tools scripts/form_automation_builder.py and scripts/scraping_toolkit.py use string concatenation and text wrapping to assemble complete Python scripts that use the requests library, then write these scripts to the local disk for execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 06:22 PM
Security Audit — agent-trust-hub — browser-automation