agent-browser
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external websites, creating a vulnerability surface where a malicious site could attempt to override agent instructions.
- Ingestion points: Web content is ingested via 'agent-browser open', 'agent-browser snapshot', and 'agent-browser get text' as documented in SKILL.md.
- Boundary markers: There are no specific boundary markers or instructions to treat web content as untrusted data.
- Capability inventory: The agent has broad capabilities including clicking, form filling, and session state management.
- Sanitization: The skill does not describe any sanitization or validation of the ingested web content.
- [COMMAND_EXECUTION]: The skill relies on executing a custom command-line interface tool 'agent-browser' to perform its functions.
Audit Metadata