vercel-sandbox
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PRIVILEGE_ESCALATION]: The skill utilizes
sudowithin the sandbox environment to install required system packages for Chromium. - [REMOTE_CODE_EXECUTION]: The skill installs the
agent-browsertool and its dependencies from npm during the sandbox environment setup. - [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted data from external URLs through browser automation, creating a surface for indirect prompt injection.
- Ingestion points: The
urlparameter inscreenshotUrlandsnapshotUrl, and thedataparameter infillAndSubmitFormare used to navigate and interact with external websites. - Boundary markers: No boundary markers or warnings to ignore embedded instructions are present in the provided code templates.
- Capability inventory: The skill has the capability to run arbitrary commands within the sandbox (
runCommand), capture screenshots, and retrieve accessibility snapshots. - Sanitization: There is no evidence of content sanitization or filtering of the external data before it is returned to the agent context.
Audit Metadata