Browser Automation

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to navigate to external websites and extract data, which exposes the agent to untrusted content that could contain hidden instructions (indirect prompt injection).
  • Ingestion points: External data enters the agent's context through tools like browser_navigate and scraping workflows defined in SKILL.md that process remote web content.
  • Boundary markers: The skill lacks explicit boundary markers or instructions to differentiate between its own logic and data retrieved from external sources.
  • Capability inventory: The skill includes navigation, element interaction (browser_click, browser_type), and data extraction capabilities as specified in the frontmatter and markdown body.
  • Sanitization: There is no evidence of sanitization or filtering logic for the content scraped from external web pages before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 10:55 AM
Security Audit — agent-trust-hub — Browser Automation