skills/browserbase/stagehand/browse/Gen Agent Trust Hub

browse

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to browse and extract data from the web, creating an attack surface where malicious website content could attempt to influence agent behavior.
  • Ingestion points: Untrusted data enters the agent context through browse open, browse snapshot, browse get html, browse get markdown, and browse cloud fetch (SKILL.md).
  • Boundary markers: No specific delimiters or instructions are provided to help the agent distinguish between tool output and instructions embedded in web content.
  • Capability inventory: The skill uses the Bash tool and can execute shell commands, write files to the local system (browse screenshot), and execute JavaScript within the browser environment (browse eval).
  • Sanitization: There is no mention of sanitizing, filtering, or escaping the HTML/Markdown content fetched from external URLs before it is processed by the agent.
  • [DYNAMIC_EXECUTION]: The browse eval command executes arbitrary JavaScript within the browser context. This is a core feature for browser automation but presents a vector for dynamic code execution if the input is influenced by untrusted data.
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the browse CLI package from NPM (npm install -g browse) and supports downloading site-specific automation scripts from the browse.sh catalog. These resources originate from the vendor's infrastructure.
  • [COMMAND_EXECUTION]: The skill relies on the Bash tool to execute browse CLI commands, which involve network operations, local browser management, and file system interactions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 03:58 PM
Security Audit — agent-trust-hub — browse