browser-use-terminal
Pass
Audited by Gen Agent Trust Hub on Jun 28, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Downloads a setup script from the developer's domain and retrieves
ripgrepbinaries from its official repository. These are trusted sources associated with the tool's core functionality. - [REMOTE_CODE_EXECUTION]: Features a Python worker that executes code provided by the model to perform browser tasks. This is a primary feature of the skill.
- [COMMAND_EXECUTION]: Allows the agent to run shell commands. Security is enhanced on Linux through the use of bubblewrap (
bwrap) for filesystem and network isolation, which mitigates the risk of unauthorized system access. - [PROMPT_INJECTION]: Includes instructions for the agent to keep certain tool-generated next steps internal, which aims to improve autonomy by automating technical recovery steps rather than prompting the user.
Audit Metadata