browser-qa
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill interacts with live web pages and parses their content (DOM, console logs, network requests), creating a surface for indirect prompt injection if an external site contains malicious instructions meant to influence the agent's behavior.
- Ingestion points: External data is ingested in
SKILL.mdduring the Smoke Test (console errors, network requests) and Interaction Test (navigating links, submitting forms). - Boundary markers: The instructions do not specify explicit delimiters or warnings for the agent to ignore instructions embedded within the target web pages.
- Capability inventory: The skill utilizes network operations for navigation and file-system operations for saving screenshots.
- Sanitization: There is no mention of sanitizing or filtering external page content to prevent command or prompt injection before the agent processes the information.
Audit Metadata