agent-browser
Pass
Audited by Gen Agent Trust Hub on May 18, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill uses tools like
agent-browser openandagent-browser snapshotto ingest and process content from external, untrusted websites. This allows for indirect prompt injection where malicious instructions hidden in a web page could manipulate the agent's behavior. \n - Ingestion points: External web content accessed via
agent-browser open <url>and element snapshots inSKILL.md. \n - Boundary markers: No delimiters or instructions to ignore embedded commands are present in the skill's documentation. \n
- Capability inventory: The skill possesses high-interaction capabilities, such as
agent-browser click,agent-browser fill, andagent-browser state save, which could be exploited if the agent is influenced by malicious web content. \n - Sanitization: There are no descriptions of sanitization or validation logic to verify the safety of content extracted from web pages.
Audit Metadata