skills/browserbase/skills/autobrowse/Gen Agent Trust Hub

autobrowse

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The evaluate.mjs script implements a security boundary by validating all tool-driven commands against an allowlist. It specifically permits only the browse CLI and uses execFileSync to prevent shell injection vulnerabilities.
  • [DYNAMIC_EXECUTION]: The codegen.mjs utility generates and executes browser automation scripts (Playwright and Stagehand). This behavior is the primary purpose of the skill, designed to verify navigation strategies created by the autonomous agent.
  • [EXTERNAL_DOWNLOADS]: The skill manages project dependencies by invoking npm install within generated task directories. These downloads target standard development libraries and vendor-owned packages (e.g., @browserbasehq/stagehand).
  • [DATA_EXPOSURE]: The skill includes a proactive lockDownTrace function that recursively applies strict POSIX permissions (0600 for files, 0700 for directories) to all session traces and screenshots, ensuring sensitive browsing artifacts are not accessible by other local users.
  • [CREDENTIALS_SAFE]: API keys (Anthropic and Browserbase) are handled via environment variables and .env files. The skill correctly instructs users to manage these secrets externally rather than hardcoding them.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:47 AM
Security Audit — agent-trust-hub — autobrowse