browser-tester

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to navigate to and inspect external web pages using Playwright, which introduces a surface for indirect prompt injection from untrusted web content.
  • Ingestion points: Untrusted data enters the agent context through the mcp__browser__fetch_browser_page, mcp__browser__inspect_browser_session, and mcp__browser__query_browser_selector tools.
  • Boundary markers: The instructions in SKILL.md do not implement delimiters or explicit warnings to the agent to disregard instructions found within the processed web content.
  • Capability inventory: The agent possesses powerful interaction capabilities including navigating sessions, clicking selectors, and filling forms. While the agents/openai.yaml specifically allows browser tools, the SKILL.md metadata also references shell access.
  • Sanitization: No sanitization, filtering, or validation of the retrieved HTML/text content is performed before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 07:23 AM
Security Audit — agent-trust-hub — browser-tester