browser-testing-with-devtools

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill explicitly identifies the threat of indirect prompt injection from untrusted web data. Evidence Chain: (1) Ingestion points: DOM content, console logs, and network responses as described in SKILL.md; (2) Boundary markers: Present in the 'Content Boundary Markers' section which defines trusted vs. untrusted context; (3) Capability inventory: DOM inspection, network monitoring, and JavaScript execution; (4) Sanitization: Strict instructions to treat browser content as data rather than instructions and to confirm extracted URLs with the user before navigation.
  • [EXTERNAL_DOWNLOADS]: Recommends configuring the chrome-devtools-mcp server using npx. This is a standard and well-known utility for the skill's documented purpose of enabling browser automation for testing.
  • [COMMAND_EXECUTION]: Outlines the use of JavaScript execution within the page context for debugging. Security is maintained by instructions that limit usage to read-only state inspection, prohibit external network requests from the page, and forbid access to sensitive authentication materials like cookies or local storage.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:30 PM
Security Audit — agent-trust-hub — browser-testing-with-devtools