browser-to-api

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill processes browser trace logs locally using Node.js standard libraries. Analysis of the scripts, including load.mjs, filter.mjs, normalize.mjs, infer.mjs, and emit.mjs, shows no evidence of network exfiltration or unauthorized file access beyond the intended .o11y run directories.
  • [SAFE]: The scripts/lib/redact.mjs module implements comprehensive redaction for sensitive information, including JWTs, emails, phone numbers, and various authentication-related headers and keys, ensuring that credentials are not inadvertently exposed in the generated OpenAPI specifications or reports.
  • [SAFE]: The HTML report generator in scripts/emit.mjs correctly escapes dynamic content derived from browser traces using an escHtml utility. This mitigates potential cross-site scripting (XSS) risks when the generated report is viewed in a browser context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:46 AM
Security Audit — agent-trust-hub — browser-to-api