agent-browser

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external websites, creating a vulnerability surface where a malicious site could attempt to override agent instructions.
  • Ingestion points: Web content is ingested via 'agent-browser open', 'agent-browser snapshot', and 'agent-browser get text' as documented in SKILL.md.
  • Boundary markers: There are no specific boundary markers or instructions to treat web content as untrusted data.
  • Capability inventory: The agent has broad capabilities including clicking, form filling, and session state management.
  • Sanitization: The skill does not describe any sanitization or validation of the ingested web content.
  • [COMMAND_EXECUTION]: The skill relies on executing a custom command-line interface tool 'agent-browser' to perform its functions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 11:03 PM
Security Audit — agent-trust-hub — agent-browser