cloudflare-browser

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • Potential Command Injection in Video Processing: The video.js script uses execSync to run ffmpeg with an output path provided via command-line arguments. Because this path is interpolated into a double-quoted string within a shell command, input containing shell metacharacters (such as backticks or subshell syntax) could lead to unintended command execution.
  • Ingestion points: Command-line arguments (process.argv) in scripts/video.js.
  • Boundary markers: None present; paths are interpolated directly.
  • Capability inventory: Execution of shell commands via execSync and file system writes.
  • Sanitization: Lacking for shell-sensitive characters in the output filename.
  • Dynamic Script Execution in Browser Context: The cdp-client.js library uses the Runtime.evaluate CDP command to interact with the headless browser. Methods like type and click interpolate user-supplied selectors or text into JavaScript strings without sanitization. This could allow for script injection within the controlled browser session if the input contains malicious code.
  • Ingestion points: Method arguments for type(), click(), and evaluate() in scripts/cdp-client.js.
  • Boundary markers: None; strings are wrapped in single quotes within the JS template.
  • Capability inventory: Execution of arbitrary JavaScript in the browser context via CDP.
  • Sanitization: No escaping or validation is performed on the input strings before they are sent to the browser.
  • Sensitive Information in WebSocket URLs: The skill connects to the rendering worker by passing the CDP_SECRET directly as a query parameter in the WebSocket URL. While this is the intended method for this service, passing secrets in URLs can occasionally result in their inclusion in intermediate network logs.
  • Evidence: SKILL.md, scripts/cdp-client.js, and scripts/screenshot.js all construct wss:// URLs containing the secret in the query string.
  • File System Interaction: The screenshot.js and video.js scripts write data to paths determined by user-provided arguments. This allows the skill to write files to any location where the executing process has write permissions.
  • Evidence: scripts/screenshot.js uses fs.writeFileSync(outputPath, ...) and scripts/video.js uses fs.writeFileSync and execSync to create the final output.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 04:03 PM
Security Audit — agent-trust-hub — cloudflare-browser