browser-automation
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is designed with safety-first principles, requiring user approval for all browser actions and ensuring that no sensitive credentials like passwords are stored or handled by the agent.
- [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it observes and processes content from external websites like KDP and Amazon. The skill mitigates this by requiring explicit user confirmation for actions and instructing the agent that observed page content cannot authorize any activity.
- Ingestion points: External website content processed during page inspection tasks in SKILL.md.
- Boundary markers: Explicit instructions to ignore authorization attempts within page content and mandatory human approval for all actions.
- Capability inventory: browser_drive and file_read permissions.
- Sanitization: Relying on a human confirmation gate to validate all planned actions before execution.
Audit Metadata