safe-browser
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches required libraries from the official NPM registry and downloads the Chromium browser using the Playwright utility.
- [COMMAND_EXECUTION]: Executes shell commands to copy templates, install dependencies, and run the demonstration script.
- [INDIRECT_PROMPT_INJECTION]: The skill processes content from external web pages, which constitutes an indirect prompt injection surface.
- Ingestion points: The
extractFrontPageandextractCommentsfunctions inhn-scraper-demo.mjsuse Playwright'spage.$$evalto read data from the browser's Document Object Model. - Boundary markers: The generated agent's system prompt explicitly instructs it to treat page content as untrusted and restricts its operations to the
safe_browsertool. - Capability inventory: The runtime environment maintains file-writing capabilities for generating artifacts and network access through a controlled browser instance.
- Sanitization: The
safe_browsertool enforces a strict domain allowlist (news.ycombinator.com) using CDPFetch.requestPausedinterception and only exposes high-level extraction actions rather than raw browser control.
Audit Metadata