stagehand-facade
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The
mcp_stagehand_runtool is explicitly designed to execute arbitrary JavaScript code provided at runtime for browser automation and multi-step workflows. - [INDIRECT_PROMPT_INJECTION]: The skill interacts with the open web, creating a vulnerability surface where content from external sites could influence agent behavior. • Ingestion points: Data from external URLs is ingested through snapshots and screenshots in SKILL.md. • Boundary markers: No specific delimiters or instructions are present to prevent the agent from interpreting content from web pages as instructions. • Capability inventory: The skill allows for network navigation and JavaScript execution via the Stagehand suite of tools. • Sanitization: The skill does not mention any methods for filtering or sanitizing content retrieved from the web before it is processed by the agent.
Audit Metadata