browser-skill

Warn

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill provides the bsk evaluate tool, allowing the AI agent to execute arbitrary JavaScript code within the browser context, which is a form of runtime code execution.
  • [DATA_EXFILTRATION]: The skill uses tools like bsk get-html, bsk screenshot, and bsk evaluate to access potentially sensitive data within the user's browser tabs, such as cookies and session state. The documentation includes 'Red lines' explicitly prohibiting activities like token theft and credential harvesting to mitigate this risk.
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through the processing of external web content.
  • Ingestion points: Website content is ingested via bsk snapshot, bsk observe, and bsk get-html as described in SKILL.md.
  • Boundary markers: There are no instructions for using delimiters to isolate website content from system prompts.
  • Capability inventory: The skill allows for significant browser interactions, including navigation and JavaScript execution.
  • Sanitization: The skill does not mandate sanitization of the data retrieved from web pages before processing.
  • [COMMAND_EXECUTION]: The skill requires the bsk CLI tool and interacts with the operating system via shell commands to perform browser automation tasks.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 19, 2026, 05:30 PM
Security Audit — agent-trust-hub — browser-skill