browser-trace

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the browse CLI tool (npm install -g browse), which is the official utility for interacting with the Browserbase platform.
  • [COMMAND_EXECUTION]: The skill executes various subcommands of the browse CLI (e.g., cdp, screenshot, cloud sessions) to record browser activity and retrieve platform artifacts. These commands are executed via standard Node.js process spawning methods to ensure safe argument handling.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from external websites, including DOM content, console logs, and network headers.
  • Ingestion points: Browser CDP events, DOM dumps (dom/*.html), and console logs (cdp/console/logs.jsonl) captured from the traced session.
  • Boundary markers: The skill does not implement explicit delimiters or "ignore" instructions within the captured data files, as they are intended for technical debugging and audit trails.
  • Capability inventory: The skill environment allows for file reading, grep operations, and execution of the provided Node.js scripts and browse CLI subcommands.
  • Sanitization: The query.mjs helper script parses raw browser data into structured JSON/NDJSON format but does not perform content sanitization against prompt injection, as the agent is expected to interpret this data as technical logs rather than instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 08:29 PM
Security Audit — agent-trust-hub — browser-trace