ego-browser
Fail
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSPRIVILEGE_ESCALATIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The
scripts/install.shscript downloads an application installer (DMG) fromhttps://cdn.ego.app/setup/macos/arm64/egolite.dmg(or x64 version). - [PRIVILEGE_ESCALATION]: The
scripts/install.shscript usessudoto perform administrative tasks, including removing Gatekeeper quarantine attributes viaxattr, deleting existing application directories, moving files to the/Applicationsfolder, and executing the macOSinstallerutility. - [COMMAND_EXECUTION]: The skill instructions guide the agent to execute a shell setup script and to run arbitrary Node.js code through the
ego-browserCLI using a heredoc pattern. - [DYNAMIC_EXECUTION]: The skill uses the
js()helper to evaluate code strings within the browser context and executes Node.js code strings via theego-browserCLI. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted web data and returns it to the agent, creating a surface for indirect prompt injection. * Ingestion points: Web content is ingested via
snapshotText()and various site-specific extraction scripts in thelearnings/directory (e.g.,search-extract.js,timeline.js). * Boundary markers: Scraped web content is not delimited or marked as untrusted. * Capability inventory: The agent has access to theBashtool for shell commands and can perform network requests viaserverFetchandbrowserFetch. * Sanitization: No evidence of sanitization or validation of the scraped web content before it is passed to the agent. - [DATA_EXFILTRATION]: The skill is designed to inherit the user's active browser login state, which allows the agent to access authenticated websites and potentially sensitive user data.
Recommendations
- AI detected serious security threats
Audit Metadata