skills/ethan-rio/skills/agent-browser/Gen Agent Trust Hub

agent-browser

Warn

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to install an external NPM package (agent-browser) that is not part of a pre-approved registry or well-known service list. This introduces a supply-chain risk.
  • [REMOTE_CODE_EXECUTION]: The skill uses the command agent-browser skills get [name] to fetch and load workflow instructions and templates from a remote server at runtime. Since this content is not present in the skill's static files, its behavior can change after deployment without further review.
  • [DYNAMIC_EXECUTION]: The skill is explicitly described as a 'discovery stub' that does not contain the actual usage logic. It relies on the dynamic loading of 'specialized skills' (like electron, slack, or core) to perform its primary functions.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: The tool interacts with arbitrary websites via Chrome/CDP, Electron desktop applications (VS Code, Slack, Discord, Figma, Notion, Spotify), and Slack workspace data.
  • Boundary markers: The provided file does not indicate any use of delimiters or 'ignore' instructions for the data it scrapes.
  • Capability inventory: The tool can fill forms, click buttons, extract data, and access an 'authentication vault' for session persistence.
  • Sanitization: No evidence of sanitization or filtering of accessibility-tree snapshots or DOM content before processing by the AI agent is provided.
  • [COMMAND_EXECUTION]: The skill grants the agent the ability to execute arbitrary subcommands of the agent-browser CLI via Bash, which controls browser sessions and interacts with local applications.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 10, 2026, 10:55 AM
Security Audit — agent-trust-hub — agent-browser