skills/idaibin/skills/ops-browser/Gen Agent Trust Hub

ops-browser

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted web content which serves as an attack surface for indirect prompt injection.
  • Ingestion points: Untrusted data enters the agent context via DOM inspection, console logs, and network responses across all browser modes defined in SKILL.md.
  • Boundary markers: SKILL.md and references/usage.md include defensive instructions to treat page content as untrusted and to ignore any embedded instructions that attempt to bypass safety guidelines.
  • Capability inventory: The skill utilizes capabilities for file uploads, downloads, screenshot capture, and access to browser storage and network state.
  • Sanitization: references/browser-operation-protocol.md mandates the sanitization of identity evidence, ensuring that PII like emails and tokens are not persisted or revealed.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 03:40 AM
Security Audit — agent-trust-hub — ops-browser