agent-browser
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill facilitates the installation and maintenance of the agent-browser CLI and its browser engines from remote sources.\n
- Documentation describes installation via npm, brew, and cargo.\n
- The agent-browser install and upgrade commands are used to download and update the Chromium browser engine and the tool itself.\n- [DYNAMIC_EXECUTION]: The skill includes an eval command that allows the execution of arbitrary JavaScript within the browser context.\n
- The functionality supports execution via simple expressions, Base64-encoded strings, or standard input to manage complex scripts and bypass shell escaping constraints.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the web, which creates a vulnerability surface for indirect prompt injection attacks.\n
- Ingestion points: Data is brought into the agent's context through snapshot, get text, and screenshot operations across multiple files.\n
- Boundary markers: The documentation recommends using the AGENT_BROWSER_CONTENT_BOUNDARIES environment variable to wrap external content in nonce-based delimiters.\n
- Capability inventory: The tool provides extensive interaction capabilities, including element manipulation, network request routing, and clipboard access.\n
- Sanitization: The platform provides opt-in content boundaries and domain allowlisting (AGENT_BROWSER_ALLOWED_DOMAINS) to restrict the agent's exposure to potentially malicious content.
Audit Metadata