chrome-devtools-cli

Pass

Audited by Gen Agent Trust Hub on Oct 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from web pages which could contain malicious instructions designed to manipulate the AI agent's behavior.
  • Ingestion points: Tools such as take_snapshot, list_pages, list_network_requests, and list_console_messages ingest data directly from the browser context into the agent's prompt.
  • Boundary markers: None identified in the skill instructions to delimit untrusted web content from agent instructions.
  • Capability inventory: The skill possesses high-privilege capabilities including filesystem access (full access enabled by default), upload_file, evaluate_script (JavaScript execution), and navigation controls.
  • Sanitization: No evidence of sanitization or filtering of the ingested browser data before it is processed by the AI.
  • [DYNAMIC_EXECUTION]: The skill provides a mechanism to execute arbitrary JavaScript within the browser context, which is a core feature of the tool but carries inherent risks if the logic is influenced by untrusted inputs.
  • Evidence: The evaluate_script tool allows for running inline functions (() => document.title) or loading local script files (--sourcePath /path/to/script.js).
  • [COMMAND_EXECUTION]: The skill operates as a CLI wrapper that executes system-level commands to interact with browser instances.
  • Evidence: Extensive use of the chrome-devtools CLI for operations like performance_start_trace, take_heapsnapshot, and install_extension.
  • [EXTERNAL_DOWNLOADS]: The skill documentation instructs users to install an external package from a public registry.
  • Evidence: references/installation.md recommends global installation of the chrome-devtools-mcp package via NPM.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 8, 2026, 08:21 AM