opencli-browser
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
openclitool through Bash, allowing the agent to perform complex browser interactions. Theopencli doctorcommand also allows the agent to diagnose the local environment, including checking for specific browser extensions and processes. - [DATA_EXFILTRATION]: The
browser uploadcommand enables the agent to select local file paths and upload them to a remote browser context via the Chrome DevTools Protocol (CDP). This creates a path for potentially exfiltrating sensitive local files if the agent is directed to untrusted sites. The skill also facilitates data harvesting throughbrowser networkandbrowser extractcommands. - [DYNAMIC_EXECUTION]: The
browser evalcommand allows the agent to execute arbitrary JavaScript within the browser. Although the instructions state this should be "read-only," the execution of dynamic scripts at runtime presents a standard risk factor for code injection if the agent interpolates untrusted data into the script. - [INDIRECT_PROMPT_INJECTION]: The skill's core purpose is to process untrusted external data from websites, making it susceptible to indirect prompt injection.
- Ingestion points: Data enters the agent context via
browser state,browser find,browser get,web read, andbrowser networkcommands which return page content and network traffic. - Boundary markers: The skill utilizes "structured envelopes" (JSON) to organize data, but it does not specify explicit delimiters or "ignore" instructions for the agent to use when parsing raw text or HTML from websites.
- Capability inventory: The agent has access to
Bash(opencli:*),Write, andEdittools, and can perform file uploads and JavaScript execution. - Sanitization: The instructions focus on structured output but do not describe specific sanitization or filtering of the web content before the agent processes it.
Audit Metadata