web-perf
Warn
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to add an MCP configuration that uses
npx -y chrome-devtools-mcp@latest. This directs the system to download thechrome-devtools-mcppackage from the npm registry at runtime.\n- [REMOTE_CODE_EXECUTION]: The instruction to usenpx -y chrome-devtools-mcp@latestfacilitates the execution of remote code in the user's local environment to enable the skill's auditing features.\n- [DATA_EXFILTRATION]: Through the use of tools likelist_network_requestsandget_network_request, the skill accesses full network transaction details. This can expose sensitive data such as session cookies, Authorization headers, and API keys to the agent's context during an audit.\n- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection attacks because it ingests and analyzes content from third-party websites that could influence the agent's behavior.\n - Ingestion points: Web content and DOM snapshots are retrieved using
navigate_pageandtake_snapshot(SKILL.md).\n - Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat the retrieved web content as untrusted or to ignore instructions contained within it.\n
- Capability inventory: The skill possesses capabilities to navigate the browser, start performance traces, and inspect specific network requests through the
chrome-devtoolsserver.\n - Sanitization: No sanitization or filtering logic is specified for the data gathered from the target websites.
Audit Metadata