browse
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to browse and extract data from the web, creating an attack surface where malicious website content could attempt to influence agent behavior.
- Ingestion points: Untrusted data enters the agent context through
browse open,browse snapshot,browse get html,browse get markdown, andbrowse cloud fetch(SKILL.md). - Boundary markers: No specific delimiters or instructions are provided to help the agent distinguish between tool output and instructions embedded in web content.
- Capability inventory: The skill uses the
Bashtool and can execute shell commands, write files to the local system (browse screenshot), and execute JavaScript within the browser environment (browse eval). - Sanitization: There is no mention of sanitizing, filtering, or escaping the HTML/Markdown content fetched from external URLs before it is processed by the agent.
- [DYNAMIC_EXECUTION]: The
browse evalcommand executes arbitrary JavaScript within the browser context. This is a core feature for browser automation but presents a vector for dynamic code execution if the input is influenced by untrusted data. - [EXTERNAL_DOWNLOADS]: The skill requires the installation of the
browseCLI package from NPM (npm install -g browse) and supports downloading site-specific automation scripts from thebrowse.shcatalog. These resources originate from the vendor's infrastructure. - [COMMAND_EXECUTION]: The skill relies on the
Bashtool to executebrowseCLI commands, which involve network operations, local browser management, and file system interactions.
Audit Metadata