browse
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches a BERT-small ONNX model for security classification from HuggingFace. This is used for the L4 prompt-injection defender.
- [COMMAND_EXECUTION]: Executes local system utilities to perform legitimate operations:
- Uses
osascripton macOS to bring browser windows to the foreground. - Uses
securityon macOS,secret-toolon Linux, andpowershellon Windows to access browser encryption keys for cookie importing. - Uses
gitto resolve project roots. - [INDIRECT_PROMPT_INJECTION]: As a tool that reads arbitrary web content, it is vulnerable to indirect prompt injection. The skill implements extensive mitigations:
- Centralized wrapping of all untrusted content in unique 'BEGIN/END UNTRUSTED EXTERNAL CONTENT' markers.
- Automatic detection and stripping of hidden elements (opacity, off-screen, ARIA injection patterns) before returning text to the agent.
- URL blocklist filtering for known exfiltration domains.
- Integration with an ML classifier (TestSavantAI) to score content for injection risk.
- [DYNAMIC_EXECUTION]: Executes JavaScript in the browser context via
page.evaluate()andaside repl. This is the core functionality of the skill. It also provides anevalcommand to run JS from local files, which is restricted to safe project directories.
Audit Metadata