chrome-devtools-cli
Pass
Audited by Gen Agent Trust Hub on Oct 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from web pages which could contain malicious instructions designed to manipulate the AI agent's behavior.
- Ingestion points: Tools such as
take_snapshot,list_pages,list_network_requests, andlist_console_messagesingest data directly from the browser context into the agent's prompt. - Boundary markers: None identified in the skill instructions to delimit untrusted web content from agent instructions.
- Capability inventory: The skill possesses high-privilege capabilities including filesystem access (full access enabled by default),
upload_file,evaluate_script(JavaScript execution), and navigation controls. - Sanitization: No evidence of sanitization or filtering of the ingested browser data before it is processed by the AI.
- [DYNAMIC_EXECUTION]: The skill provides a mechanism to execute arbitrary JavaScript within the browser context, which is a core feature of the tool but carries inherent risks if the logic is influenced by untrusted inputs.
- Evidence: The
evaluate_scripttool allows for running inline functions (() => document.title) or loading local script files (--sourcePath /path/to/script.js). - [COMMAND_EXECUTION]: The skill operates as a CLI wrapper that executes system-level commands to interact with browser instances.
- Evidence: Extensive use of the
chrome-devtoolsCLI for operations likeperformance_start_trace,take_heapsnapshot, andinstall_extension. - [EXTERNAL_DOWNLOADS]: The skill documentation instructs users to install an external package from a public registry.
- Evidence:
references/installation.mdrecommends global installation of thechrome-devtools-mcppackage via NPM.
Audit Metadata