opencli-browser

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the opencli tool through Bash, allowing the agent to perform complex browser interactions. The opencli doctor command also allows the agent to diagnose the local environment, including checking for specific browser extensions and processes.
  • [DATA_EXFILTRATION]: The browser upload command enables the agent to select local file paths and upload them to a remote browser context via the Chrome DevTools Protocol (CDP). This creates a path for potentially exfiltrating sensitive local files if the agent is directed to untrusted sites. The skill also facilitates data harvesting through browser network and browser extract commands.
  • [DYNAMIC_EXECUTION]: The browser eval command allows the agent to execute arbitrary JavaScript within the browser. Although the instructions state this should be "read-only," the execution of dynamic scripts at runtime presents a standard risk factor for code injection if the agent interpolates untrusted data into the script.
  • [INDIRECT_PROMPT_INJECTION]: The skill's core purpose is to process untrusted external data from websites, making it susceptible to indirect prompt injection.
  • Ingestion points: Data enters the agent context via browser state, browser find, browser get, web read, and browser network commands which return page content and network traffic.
  • Boundary markers: The skill utilizes "structured envelopes" (JSON) to organize data, but it does not specify explicit delimiters or "ignore" instructions for the agent to use when parsing raw text or HTML from websites.
  • Capability inventory: The agent has access to Bash(opencli:*), Write, and Edit tools, and can perform file uploads and JavaScript execution.
  • Sanitization: The instructions focus on structured output but do not describe specific sanitization or filtering of the web content before the agent processes it.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 11:41 AM
Security Audit — agent-trust-hub — opencli-browser