agent-browser

Pass

Audited by Gen Agent Trust Hub on Apr 22, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill creates a significant surface for Indirect Prompt Injection by navigating to and reading content from arbitrary, untrusted web pages. A malicious site could include hidden instructions to compromise the agent. Mandatory Evidence Chain: Ingestion points include 'open', 'snapshot', and 'execute' functions (SKILL.md); no boundary markers or delimiters for untrusted content were identified; capabilities include JavaScript execution, form filling, and file uploads; no evidence of web content sanitization before processing was found.\n- [COMMAND_EXECUTION]: The skill includes an 'execute' function designed to run arbitrary JavaScript code within the browser context. While a fundamental feature for automation, it can be abused to access sensitive data like session cookies or perform unauthorized actions on the user's behalf. Evidence: Documentation in references/commands.md and references/authentication.md.\n- [DATA_EXFILTRATION]: The 'interact' tool supports an 'upload' action that allows the agent to transmit local files to remote websites. This represents a potential exfiltration path if an attacker successfully influences the agent to target sensitive local files. Evidence: Action reference in SKILL.md and references/commands.md.\n- [EXTERNAL_DOWNLOADS]: The documentation points to an external installation resource for the required CLI on the vendor's GitHub organization. Evidence: Installation link in SKILL.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 22, 2026, 04:26 PM
Security Audit — agent-trust-hub — agent-browser