browser-qa

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill interacts with live web pages and parses their content (DOM, console logs, network requests), creating a surface for indirect prompt injection if an external site contains malicious instructions meant to influence the agent's behavior.
  • Ingestion points: External data is ingested in SKILL.md during the Smoke Test (console errors, network requests) and Interaction Test (navigating links, submitting forms).
  • Boundary markers: The instructions do not specify explicit delimiters or warnings for the agent to ignore instructions embedded within the target web pages.
  • Capability inventory: The skill utilizes network operations for navigation and file-system operations for saving screenshots.
  • Sanitization: There is no mention of sanitizing or filtering external page content to prevent command or prompt injection before the agent processes the information.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:39 PM
Security Audit — agent-trust-hub — browser-qa