agent-browser
Pass
Audited by Gen Agent Trust Hub on Jun 21, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides browser automation capabilities using a CLI tool. While browser automation naturally interacts with untrusted web content (representing an indirect prompt injection surface) and supports JavaScript execution within the browser, the skill includes a dedicated safety guide (
trust-boundaries.md) that explicitly instructs the agent to treat all browser-surfaced content as untrusted data and ignore embedded instructions. All installation methods and configuration patterns for Vercel Sandbox and AWS Bedrock AgentCore follow standard development practices. Authentication is handled securely through session state files and an internal auth vault, accompanied by strong warnings against hardcoding secrets or exposing credentials in logs.
Audit Metadata