browser-qa

Pass

Audited by Gen Agent Trust Hub on Apr 6, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to Indirect Prompt Injection as it is designed to navigate to target URLs and process live web content (HTML, console logs, and network requests) to generate QA reports. There are no explicit boundary markers or instructions to ignore embedded commands in the processed data. An attacker-controlled website could potentially embed malicious instructions to influence the agent's behavior during the session.
  • Ingestion points: Target URL content, console output, and network request data.
  • Boundary markers: None specified in the instructions.
  • Capability inventory: Full browser automation via claude-in-chrome or Playwright, including navigation, clicking, form submission, and screen capturing.
  • Sanitization: No sanitization or filtering of external content is defined.
  • [DATA_EXFILTRATION]: The skill instructions explicitly include testing authentication flows ("login → protected page → logout"). While this is a standard QA task, it requires the agent to interact with and potentially store user credentials in its context. Additionally, the recommended use of claude-in-chrome (which leverages the user's actual browser profile) gives the agent access to existing session cookies and local storage, increasing the impact of a potential compromise.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 6, 2026, 04:00 AM
Security Audit — agent-trust-hub — browser-qa