managing-puppeteer

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFE
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill uses node -e to execute inline JavaScript for discovering the Puppeteer version and the browser's executable path. This execution is static and limited to environment discovery.\n- [INDIRECT_PROMPT_INJECTION]: The skill reads and searches through local JavaScript and TypeScript files. This presents an indirect prompt injection surface as it ingests potentially untrusted data into the agent's context. However, the skill includes explicit instructions against executing or modifying scripts without user approval, which serves as a safety boundary.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 04:22 PM
Security Audit — agent-trust-hub — managing-puppeteer