agent-browser
Fail
Audited by Snyk on Aug 19, 2026
Risk Level: CRITICAL
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 0.90). The skill contains multiple examples that embed plaintext secrets (e.g., literal passwords and a credit-card number) directly in CLI commands and automation steps, which would require an LLM-driven agent to emit or handle those secret values verbatim — a high exfiltration risk.
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 1.00). These URLs include an explicitly malicious domain (https://malicious.com) which is not a trusted vendor or package source and is shown in the skill as an example of a blocked/untrusted domain, so it represents a suspicious download/distribution source.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The workflow described by SKILL.md uses
agent-browser open <url>and thenagent-browser snapshot -i/get text bodyto read page accessibility/text from whatever URL is navigated to, meaning outsider-authored free text from attacker-controlled web pages can be ingested at runtime.
Issues (3)
W007
HIGHInsecure credential handling detected in skill instructions.
E005
CRITICALSuspicious download URL detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata