browser-skill
Warn
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: MEDIUMREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill provides the
bsk evaluatetool, allowing the AI agent to execute arbitrary JavaScript code within the browser context, which is a form of runtime code execution. - [DATA_EXFILTRATION]: The skill uses tools like
bsk get-html,bsk screenshot, andbsk evaluateto access potentially sensitive data within the user's browser tabs, such as cookies and session state. The documentation includes 'Red lines' explicitly prohibiting activities like token theft and credential harvesting to mitigate this risk. - [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through the processing of external web content.
- Ingestion points: Website content is ingested via
bsk snapshot,bsk observe, andbsk get-htmlas described inSKILL.md. - Boundary markers: There are no instructions for using delimiters to isolate website content from system prompts.
- Capability inventory: The skill allows for significant browser interactions, including navigation and JavaScript execution.
- Sanitization: The skill does not mandate sanitization of the data retrieved from web pages before processing.
- [COMMAND_EXECUTION]: The skill requires the
bskCLI tool and interacts with the operating system via shell commands to perform browser automation tasks.
Audit Metadata