remote-browser
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill fetches content from external web pages via the
/fetchand/sessionendpoints and returns the extracted text and links to the agent. This represents an attack surface where a malicious website could include hidden instructions to manipulate the agent. - Ingestion points: Data from external URLs is ingested through the Cloudflare Worker's API and processed by scripts like
scripts/instances.sh. - Boundary markers: The skill does not define explicit delimiters or use specific instructions to prevent the agent from obeying instructions embedded within the fetched web content.
- Capability inventory: The skill can execute shell scripts, write to the local filesystem (under
~/.config/remote-browser), and perform network operations. - Sanitization: No filtering or sanitization is performed on the text retrieved from target websites before it is presented to the agent.
- [COMMAND_EXECUTION]: The skill relies on executing local bash scripts (
scripts/deploy.sh,scripts/check-env.sh, andscripts/instances.sh) to manage the environment and deployment lifecycle. These scripts perform operations like directory creation, file writing, and calling the Wrangler CLI. - [EXTERNAL_DOWNLOADS]: The deployment process involves downloading the Wrangler CLI via
npxand installing Node.js dependencies throughnpm install. These resources are fetched from Cloudflare and the official NPM registry to facilitate the intended cloud deployment.
Audit Metadata