browser-tester
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to navigate to and inspect external web pages using Playwright, which introduces a surface for indirect prompt injection from untrusted web content.
- Ingestion points: Untrusted data enters the agent context through the
mcp__browser__fetch_browser_page,mcp__browser__inspect_browser_session, andmcp__browser__query_browser_selectortools. - Boundary markers: The instructions in
SKILL.mddo not implement delimiters or explicit warnings to the agent to disregard instructions found within the processed web content. - Capability inventory: The agent possesses powerful interaction capabilities including navigating sessions, clicking selectors, and filling forms. While the
agents/openai.yamlspecifically allows browser tools, theSKILL.mdmetadata also references shell access. - Sanitization: No sanitization, filtering, or validation of the retrieved HTML/text content is performed before it is processed by the agent.
Audit Metadata