eve-web-ui-testing-agent-browser

Warn

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: MEDIUMOBFUSCATIONDYNAMIC_EXECUTIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [OBFUSCATION]: The skill documents and encourages the use of Base64-encoded JavaScript execution via the agent-browser eval -b command to avoid shell escaping issues.\n
  • Evidence: agent-browser eval -b "ZG9jdW1lbnQucXVlcnlTZWxlY3RvcignW3NyYyo9Il9uZXh0Il0nKQ==" in references/commands.md.\n- [DYNAMIC_EXECUTION]: The agent-browser eval command (and its --stdin and -b variants) allows for the execution of arbitrary JavaScript within the browser context.\n
  • Evidence: Multiple references in references/commands.md regarding eval usage for page manipulation.\n- [CREDENTIALS_UNSAFE]: The skill provides instructions for configuring authenticated proxies by including plain-text credentials directly in the proxy URL, which can be exposed in process logs or environment variables.\n
  • Evidence: export HTTP_PROXY="http://username:password@proxy.example.com:8080" in references/proxy-support.md.\n
  • Evidence: Instructions mention setting environment variables for API keys (e.g., BROWSERBASE_API_KEY) in plain text.\n- [INDIRECT_PROMPT_INJECTION]: The skill is designed to navigate to and extract data from external, untrusted websites, creating a surface for indirect prompt injection if those sites contain malicious instructions targeted at the agent.\n
  • Ingestion points: agent-browser open <url>, agent-browser snapshot, and agent-browser get text in SKILL.md and templates/capture-workflow.sh.\n
  • Boundary markers: None present to distinguish web content from instructions.\n
  • Capability inventory: Browser interaction (click, fill), file system access (screenshot, PDF, state save), and arbitrary JavaScript execution (eval).\n
  • Sanitization: No sanitization or validation of extracted web content is documented.\n- [EXTERNAL_DOWNLOADS]: The skill installs software from external sources, including a global npm package and an upstream skill from a well-known service.\n
  • Evidence: npm install -g agent-browser and eve skill install https://github.com/vercel-labs/agent-browser in SKILL.md.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 16, 2026, 07:51 AM
Security Audit — agent-trust-hub — eve-web-ui-testing-agent-browser