browser-testing-with-devtools
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill explicitly identifies the threat of indirect prompt injection from untrusted web data. Evidence Chain: (1) Ingestion points: DOM content, console logs, and network responses as described in SKILL.md; (2) Boundary markers: Present in the 'Content Boundary Markers' section which defines trusted vs. untrusted context; (3) Capability inventory: DOM inspection, network monitoring, and JavaScript execution; (4) Sanitization: Strict instructions to treat browser content as data rather than instructions and to confirm extracted URLs with the user before navigation.
- [EXTERNAL_DOWNLOADS]: Recommends configuring the chrome-devtools-mcp server using npx. This is a standard and well-known utility for the skill's documented purpose of enabling browser automation for testing.
- [COMMAND_EXECUTION]: Outlines the use of JavaScript execution within the page context for debugging. Security is maintained by instructions that limit usage to read-only state inspection, prohibit external network requests from the page, and forbid access to sensitive authentication materials like cookies or local storage.
Audit Metadata