stagehand-facade

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The mcp_stagehand_run tool is explicitly designed to execute arbitrary JavaScript code provided at runtime for browser automation and multi-step workflows.
  • [INDIRECT_PROMPT_INJECTION]: The skill interacts with the open web, creating a vulnerability surface where content from external sites could influence agent behavior. • Ingestion points: Data from external URLs is ingested through snapshots and screenshots in SKILL.md. • Boundary markers: No specific delimiters or instructions are present to prevent the agent from interpreting content from web pages as instructions. • Capability inventory: The skill allows for network navigation and JavaScript execution via the Stagehand suite of tools. • Sanitization: The skill does not mention any methods for filtering or sanitizing content retrieved from the web before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 06:37 PM
Security Audit — agent-trust-hub — stagehand-facade