browser-qa
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect prompt injection vulnerability surface. The skill instructs the agent to navigate to external URLs and interact with their content, which is a vector for malicious instructions embedded in the target pages.
- Ingestion points: External URLs provided for smoke testing and interaction verification (SKILL.md).
- Boundary markers: Not specified; the agent is not instructed to ignore embedded instructions in the DOM.
- Capability inventory: Browser automation including clicking, form submission, and screenshot capture via MCP tools.
- Sanitization: No content filtering or validation of the ingested web data is defined.
Audit Metadata