dogfood
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill interacts with external web applications and processes their content, creating a surface for indirect prompt injection. A malicious website could attempt to manipulate the agent's logic through content or console output.
- Ingestion points: Target URL content captured via
agent-browser snapshot, and browser console logs/errors. - Boundary markers: None. The instructions do not specify how to isolate site content from agent instructions.
- Capability inventory: The agent uses
Bashfor file operations andagent-browserfor browser interactions. - Sanitization: No sanitization is performed on the ingested web data.
- [DATA_EXPOSURE]: The skill instructions include steps to capture and store browser session state, which may contain sensitive authentication tokens or cookies.
- Evidence: The workflow in
SKILL.mdexplicitly commands the agent to save the session state to a file (agent-browser --session {SESSION} state save {OUTPUT_DIR}/auth-state.json). While this is functional for testing, it creates a local file containing sensitive credentials that could be exposed if the output directory is not properly managed.
Audit Metadata