browser-automation
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to guide agents in browser automation and web scraping, creating a surface where the agent ingests untrusted content from the web. This data could contain instructions designed to manipulate the agent's behavior.
- Ingestion points: External web content processed during scraping or automation tasks (SKILL.md).
- Boundary markers: The skill does not provide instructions for using boundary markers or delimiting untrusted web data from system instructions.
- Capability inventory: Browser control, headless browser interaction, and UI automation.
- Sanitization: No patterns are provided for sanitizing or filtering external HTML/text content before processing.
- [NO_CODE]: The skill consists exclusively of markdown instructions and metadata. It does not include any executable scripts, configuration files, or binaries.
Audit Metadata