cloudflare-browser
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- Potential Command Injection in Video Processing: The
video.jsscript usesexecSyncto runffmpegwith an output path provided via command-line arguments. Because this path is interpolated into a double-quoted string within a shell command, input containing shell metacharacters (such as backticks or subshell syntax) could lead to unintended command execution. - Ingestion points: Command-line arguments (
process.argv) inscripts/video.js. - Boundary markers: None present; paths are interpolated directly.
- Capability inventory: Execution of shell commands via
execSyncand file system writes. - Sanitization: Lacking for shell-sensitive characters in the output filename.
- Dynamic Script Execution in Browser Context: The
cdp-client.jslibrary uses theRuntime.evaluateCDP command to interact with the headless browser. Methods liketypeandclickinterpolate user-supplied selectors or text into JavaScript strings without sanitization. This could allow for script injection within the controlled browser session if the input contains malicious code. - Ingestion points: Method arguments for
type(),click(), andevaluate()inscripts/cdp-client.js. - Boundary markers: None; strings are wrapped in single quotes within the JS template.
- Capability inventory: Execution of arbitrary JavaScript in the browser context via CDP.
- Sanitization: No escaping or validation is performed on the input strings before they are sent to the browser.
- Sensitive Information in WebSocket URLs: The skill connects to the rendering worker by passing the
CDP_SECRETdirectly as a query parameter in the WebSocket URL. While this is the intended method for this service, passing secrets in URLs can occasionally result in their inclusion in intermediate network logs. - Evidence:
SKILL.md,scripts/cdp-client.js, andscripts/screenshot.jsall constructwss://URLs containing the secret in the query string. - File System Interaction: The
screenshot.jsandvideo.jsscripts write data to paths determined by user-provided arguments. This allows the skill to write files to any location where the executing process has write permissions. - Evidence:
scripts/screenshot.jsusesfs.writeFileSync(outputPath, ...)andscripts/video.jsusesfs.writeFileSyncandexecSyncto create the final output.
Audit Metadata