workday-browser

Warn

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides scripts and commands to terminate the user's running browser process and relaunch it with the --remote-debugging-port and --user-data-dir flags. This procedure grants the agent full programmatic control over the user's authenticated browser profile and all its active sessions.\n- [REMOTE_CODE_EXECUTION]: The skill uses a pattern of generating Node.js scripts from templates and executing them locally to perform browser automation tasks. This dynamic code generation allows for arbitrary actions within the browser context.\n- [DATA_EXFILTRATION]: The skill is designed to scrape and extract highly sensitive personal and financial data from the Workday enterprise tenant, specifically employee payslips, absence balances, and team roster/organizational data. It includes capabilities to download these records as PDFs or Excel files.\n- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the playwright npm package to function. While Playwright is a standard automation library, its use here facilitates the hijacking of the user's active browser session.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 14, 2026, 11:23 PM
Security Audit — agent-trust-hub — workday-browser