agent-browser

Pass

Audited by Gen Agent Trust Hub on Jun 24, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill instructs the user to install the 'agent-browser' package globally from the npm registry and references upstream configuration from the Vercel Labs GitHub repository. These dependencies are functional requirements for the skill's purpose.
  • [COMMAND_EXECUTION]: The skill executes shell commands to manage browser sessions, including starting Google Chrome with remote debugging flags and using 'curl' to interface with the local DevTools port. These commands are necessary for local browser automation.
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies the risk of instructions embedded in processed web data and provides clear safety rules to mitigate this risk.
  • Ingestion points: Web page snapshots and content extracted via the agent-browser CLI (SKILL.md).
  • Boundary markers: Explicit safety rules instruct the agent to treat page content as untrusted evidence rather than instructions.
  • Capability inventory: The skill possesses shell execution capabilities and file writing for screenshots (SKILL.md).
  • Sanitization: No automated sanitization is described, relying instead on instructional guardrails to ignore embedded commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 24, 2026, 01:38 PM
Security Audit — agent-trust-hub — agent-browser