browser-automation

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to guide agents in browser automation and web scraping, creating a surface where the agent ingests untrusted content from the web. This data could contain instructions designed to manipulate the agent's behavior.
  • Ingestion points: External web content processed during scraping or automation tasks (SKILL.md).
  • Boundary markers: The skill does not provide instructions for using boundary markers or delimiting untrusted web data from system instructions.
  • Capability inventory: Browser control, headless browser interaction, and UI automation.
  • Sanitization: No patterns are provided for sanitizing or filtering external HTML/text content before processing.
  • [NO_CODE]: The skill consists exclusively of markdown instructions and metadata. It does not include any executable scripts, configuration files, or binaries.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 02:31 PM
Security Audit — agent-trust-hub — browser-automation