skills/hk-hub/agentskills/chrome-cdp/Gen Agent Trust Hub

chrome-cdp

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/cdp.mjs spawns background daemon processes and communicates using local Unix domain sockets or Windows Named Pipes. This setup allows for persistent per-tab automation sessions.\n- [PROMPT_INJECTION]: The skill is highly vulnerable to Indirect Prompt Injection (Category 8). An agent using this skill to inspect or interact with a webpage could be tricked by hidden instructions on that page into executing unintended commands.\n
  • Ingestion points: Untrusted data enters the agent context through the snap (accessibility tree), html (source code), and eval (script results) commands in scripts/cdp.mjs.\n
  • Boundary markers: The instructions lack specific markers or warnings to help the agent distinguish between user instructions and instructions found within processed web content.\n
  • Capability inventory: The skill provides high-privilege capabilities including arbitrary JavaScript execution (eval), URL navigation (nav), and raw protocol command passthrough (evalraw) in scripts/cdp.mjs.\n
  • Sanitization: Content read from external websites is not sanitized or escaped before being returned to the agent's context.\n- [DATA_EXFILTRATION]: Although the skill does not exfiltrate data itself, its ability to read page content, cookies, and local storage (via eval or evalraw) provides the necessary tools for an agent to be manipulated into exfiltrating sensitive session information.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:30 PM
Security Audit — agent-trust-hub — chrome-cdp