agent-browser
Warn
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to install an external NPM package (
agent-browser) that is not part of a pre-approved registry or well-known service list. This introduces a supply-chain risk. - [REMOTE_CODE_EXECUTION]: The skill uses the command
agent-browser skills get [name]to fetch and load workflow instructions and templates from a remote server at runtime. Since this content is not present in the skill's static files, its behavior can change after deployment without further review. - [DYNAMIC_EXECUTION]: The skill is explicitly described as a 'discovery stub' that does not contain the actual usage logic. It relies on the dynamic loading of 'specialized skills' (like
electron,slack, orcore) to perform its primary functions. - [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: The tool interacts with arbitrary websites via Chrome/CDP, Electron desktop applications (VS Code, Slack, Discord, Figma, Notion, Spotify), and Slack workspace data.
- Boundary markers: The provided file does not indicate any use of delimiters or 'ignore' instructions for the data it scrapes.
- Capability inventory: The tool can fill forms, click buttons, extract data, and access an 'authentication vault' for session persistence.
- Sanitization: No evidence of sanitization or filtering of accessibility-tree snapshots or DOM content before processing by the AI agent is provided.
- [COMMAND_EXECUTION]: The skill grants the agent the ability to execute arbitrary subcommands of the
agent-browserCLI via Bash, which controls browser sessions and interacts with local applications.
Audit Metadata