skills/garrytan/gstack/browse/Gen Agent Trust Hub

browse

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches a BERT-small ONNX model for security classification from HuggingFace. This is used for the L4 prompt-injection defender.
  • [COMMAND_EXECUTION]: Executes local system utilities to perform legitimate operations:
  • Uses osascript on macOS to bring browser windows to the foreground.
  • Uses security on macOS, secret-tool on Linux, and powershell on Windows to access browser encryption keys for cookie importing.
  • Uses git to resolve project roots.
  • [INDIRECT_PROMPT_INJECTION]: As a tool that reads arbitrary web content, it is vulnerable to indirect prompt injection. The skill implements extensive mitigations:
  • Centralized wrapping of all untrusted content in unique 'BEGIN/END UNTRUSTED EXTERNAL CONTENT' markers.
  • Automatic detection and stripping of hidden elements (opacity, off-screen, ARIA injection patterns) before returning text to the agent.
  • URL blocklist filtering for known exfiltration domains.
  • Integration with an ML classifier (TestSavantAI) to score content for injection risk.
  • [DYNAMIC_EXECUTION]: Executes JavaScript in the browser context via page.evaluate() and aside repl. This is the core functionality of the skill. It also provides an eval command to run JS from local files, which is restricted to safe project directories.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 07:14 AM
Security Audit — agent-trust-hub — browse