chrome-devtools
Fail
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: HIGHCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The
scripts/screenshot.jsfile contains a command injection vulnerability within thecompressImageIfNeededfunction. The script usesexecSyncto run ImageMagick commands (e.g.,magick "${filePath}" ...). ThefilePathvariable is derived directly from the user-supplied--outputargument. Because this path is interpolated into a shell command string without sanitization against shell metacharacters, an attacker could achieve arbitrary command execution by providing a malicious filename (e.g., using subshell syntax like$(command)). - [REMOTE_CODE_EXECUTION]: The
scripts/evaluate.jsscript allows for the execution of arbitrary JavaScript within the browser's page context usingeval()via Puppeteer'spage.evaluate(). This creates a high-capability execution surface that can be leveraged to interact with or extract data from any website the browser navigates to. - [COMMAND_EXECUTION]: The installation scripts
scripts/install.shandscripts/install-deps.shexecute system commands with elevated privileges (sudo) to install dependencies and update package managers (apt-get,dnf,pacman). While standard for setting up browser environments on Linux, these operations involve privileged access to the host system. - [REMOTE_CODE_EXECUTION]: The skill presents a surface for indirect prompt injection due to its combination of data ingestion and high-privilege capabilities. It reads untrusted data from external websites via
scripts/snapshot.js(DOM snapshots),scripts/console.js(console logs), andscripts/network.js(network traffic). This data is returned to the agent context without boundary markers or sanitization. Combined with the skill's ability to write to the local file system and execute browser-side scripts, this creates a path for malicious web content to influence agent behavior.
Recommendations
- AI detected serious security threats
Audit Metadata