Browser Automation
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to navigate to external websites and extract data, which exposes the agent to untrusted content that could contain hidden instructions (indirect prompt injection).
- Ingestion points: External data enters the agent's context through tools like
browser_navigateand scraping workflows defined inSKILL.mdthat process remote web content. - Boundary markers: The skill lacks explicit boundary markers or instructions to differentiate between its own logic and data retrieved from external sources.
- Capability inventory: The skill includes navigation, element interaction (
browser_click,browser_type), and data extraction capabilities as specified in the frontmatter and markdown body. - Sanitization: There is no evidence of sanitization or filtering logic for the content scraped from external web pages before it is processed by the agent.
Audit Metadata