electron
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions to launch various desktop applications (e.g., Slack, VS Code, Discord) with the
--remote-debugging-portflag enabled. This allows the agent to execute commands and interact with the application's internal UI using the Chrome DevTools Protocol (CDP). - [DATA_EXFILTRATION]: By design, the skill allows the agent to connect to and extract data from sensitive applications, including communication tools (Slack, Discord), development environments (VS Code), and productivity apps (Notion, 1Password). This configuration enables the agent to read private messages, source code, and other sensitive information.
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection.
- Ingestion points: The agent reads and processes data from external applications, including Slack messages, Discord channels, and webview content (found in
SKILL.md). - Boundary markers: There are no markers or instructions provided to distinguish between application data and intended agent commands.
- Capability inventory: The agent has extensive capabilities to interact with the system via the
agent-browsertools, including clicking, typing, and extracting state. - Sanitization: No sanitization or validation of the ingested application data is mentioned or implemented.
Audit Metadata