autobrowse
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The
evaluate.mjsscript implements a security boundary by validating all tool-driven commands against an allowlist. It specifically permits only thebrowseCLI and usesexecFileSyncto prevent shell injection vulnerabilities. - [DYNAMIC_EXECUTION]: The
codegen.mjsutility generates and executes browser automation scripts (Playwright and Stagehand). This behavior is the primary purpose of the skill, designed to verify navigation strategies created by the autonomous agent. - [EXTERNAL_DOWNLOADS]: The skill manages project dependencies by invoking
npm installwithin generated task directories. These downloads target standard development libraries and vendor-owned packages (e.g.,@browserbasehq/stagehand). - [DATA_EXPOSURE]: The skill includes a proactive
lockDownTracefunction that recursively applies strict POSIX permissions (0600 for files, 0700 for directories) to all session traces and screenshots, ensuring sensitive browsing artifacts are not accessible by other local users. - [CREDENTIALS_SAFE]: API keys (Anthropic and Browserbase) are handled via environment variables and
.envfiles. The skill correctly instructs users to manage these secrets externally rather than hardcoding them.
Audit Metadata