browser-use

Fail

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: HIGHCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONCREDENTIALS_UNSAFEPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The browser-use python command allows for the execution of arbitrary Python statements within the agent's environment. This provides a vector for performing host-level operations entirely unrelated to browser automation.
  • [REMOTE_CODE_EXECUTION]: The skill facilitates dynamic code execution through browser-use eval, which runs JavaScript in the browser context. Additionally, the browser-use profile update command downloads and updates an external binary (profile-use) at runtime.
  • [DATA_EXFILTRATION]: The browser-use profile sync --all command transmits entire browser profiles to a cloud service. These profiles typically contain sensitive information, including authentication cookies, browsing history, and saved credentials.
  • [DATA_EXFILTRATION]: The skill can expose local network services to the internet via the browser-use tunnel command, which utilizes Cloudflare tunnels to create public URLs for local ports.
  • [CREDENTIALS_UNSAFE]: The tool handles cloud API keys through browser-use cloud login and stores them in a local configuration file at ~/.browser-use/config.json.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it ingests untrusted data from the web to drive its logic.
  • Ingestion points: Web content retrieved via browser-use open, browser-use state, and browser-use get html (SKILL.md).
  • Boundary markers: None identified; instructions do not provide delimiters or warnings to ignore instructions found within the processed web data.
  • Capability inventory: Includes arbitrary Python execution (browser-use python), file system modification (screenshot saving, cookie exporting), and network tunneling.
  • Sanitization: There is no mention of sanitizing or escaping web content before it is processed by the agent.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
May 14, 2026, 07:01 AM
Security Audit — agent-trust-hub — browser-use