browser-testing

Pass

Audited by Gen Agent Trust Hub on May 29, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the ironbee-browser-devtools-cli tool via the Bash tool to perform automated browser actions and UI testing.\n- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface because it retrieves and processes content from external websites.\n
  • Ingestion points: Untrusted data enters the agent's context through the content get-as-html and content get-as-text commands defined in SKILL.md.\n
  • Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions to isolate processed web content from the agent's primary directives.\n
  • Capability inventory: The skill facilitates powerful interactions, including element manipulation, navigation, and the execution of scripts via the run execute command.\n
  • Sanitization: No mechanisms for sanitizing or validating retrieved web content are implemented prior to its processing by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
May 29, 2026, 01:38 AM
Security Audit — agent-trust-hub — browser-testing