baoyu-danger-gemini-web

Warn

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill launches and interacts with local browser processes (Chrome, Chromium, Edge) via the baoyu-chrome-cdp library to perform automated session handling and login flows.
  • [DATA_EXFILTRATION]: Specifically uses the Network.getCookies CDP command to extract sensitive authentication tokens (__Secure-1PSID, __Secure-1PSIDTS) from the user's active browser session and caches them to a local JSON file.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: Reads external data through the --promptfiles CLI argument and reference image files for vision processing.
  • Boundary markers: None; content from external files is interpolated into the API request payload without delimiters or instructions to ignore embedded commands.
  • Capability inventory: Network access to Google services, local file system writes for session/cookie storage, and browser process control.
  • Sanitization: No validation or sanitization is performed on file contents before they are transmitted to the LLM backend.
  • [EXTERNAL_DOWNLOADS]: Connects to various Google domains (gemini.google.com, googleapis.com) to upload user data and fetch model outputs using reverse-engineered headers and protocols.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 14, 2026, 03:17 PM
Security Audit — agent-trust-hub — baoyu-danger-gemini-web