open-browser-use

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill directs users to install the CLI and SDKs from official registries (NPM, PyPI, Homebrew). It also mentions downloading an extension ZIP from GitHub Releases for beta setup.\n- [COMMAND_EXECUTION]: The skill uses the 'open-browser-use' CLI to interact with Chrome, including using 'cdp' commands that can execute arbitrary JavaScript in the browser context via 'Runtime.evaluate'.\n- [PROMPT_INJECTION]: As the skill involves browsing external websites, it is susceptible to indirect prompt injection. However, it explicitly instructs agents to ignore sensitive user data and requires human-in-the-loop confirmation for any actions that modify the state or access private information.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 05:20 AM