baoyu-danger-gemini-web
Warn
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill launches and interacts with local browser processes (Chrome, Chromium, Edge) via the
baoyu-chrome-cdplibrary to perform automated session handling and login flows. - [DATA_EXFILTRATION]: Specifically uses the
Network.getCookiesCDP command to extract sensitive authentication tokens (__Secure-1PSID,__Secure-1PSIDTS) from the user's active browser session and caches them to a local JSON file. - [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: Reads external data through the
--promptfilesCLI argument and reference image files for vision processing. - Boundary markers: None; content from external files is interpolated into the API request payload without delimiters or instructions to ignore embedded commands.
- Capability inventory: Network access to Google services, local file system writes for session/cookie storage, and browser process control.
- Sanitization: No validation or sanitization is performed on file contents before they are transmitted to the LLM backend.
- [EXTERNAL_DOWNLOADS]: Connects to various Google domains (
gemini.google.com,googleapis.com) to upload user data and fetch model outputs using reverse-engineered headers and protocols.
Audit Metadata