browser-to-api
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill processes browser trace logs locally using Node.js standard libraries. Analysis of the scripts, including
load.mjs,filter.mjs,normalize.mjs,infer.mjs, andemit.mjs, shows no evidence of network exfiltration or unauthorized file access beyond the intended.o11yrun directories. - [SAFE]: The
scripts/lib/redact.mjsmodule implements comprehensive redaction for sensitive information, including JWTs, emails, phone numbers, and various authentication-related headers and keys, ensuring that credentials are not inadvertently exposed in the generated OpenAPI specifications or reports. - [SAFE]: The HTML report generator in
scripts/emit.mjscorrectly escapes dynamic content derived from browser traces using anescHtmlutility. This mitigates potential cross-site scripting (XSS) risks when the generated report is viewed in a browser context.
Audit Metadata