vercel-sandbox

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PRIVILEGE_ESCALATION]: The skill utilizes sudo within the sandbox environment to install required system packages for Chromium.
  • [REMOTE_CODE_EXECUTION]: The skill installs the agent-browser tool and its dependencies from npm during the sandbox environment setup.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted data from external URLs through browser automation, creating a surface for indirect prompt injection.
  • Ingestion points: The url parameter in screenshotUrl and snapshotUrl, and the data parameter in fillAndSubmitForm are used to navigate and interact with external websites.
  • Boundary markers: No boundary markers or warnings to ignore embedded instructions are present in the provided code templates.
  • Capability inventory: The skill has the capability to run arbitrary commands within the sandbox (runCommand), capture screenshots, and retrieve accessibility snapshots.
  • Sanitization: There is no evidence of content sanitization or filtering of the external data before it is returned to the agent context.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:31 PM
Security Audit — agent-trust-hub — vercel-sandbox