browser-debugger

Pass

Audited by Gen Agent Trust Hub on May 12, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill consists entirely of markdown instructions without accompanying scripts, binaries, or automated installation steps. The focus is on manual diagnostic procedures and minimal client-side fixes.
  • [PROMPT_INJECTION]: Indirect Prompt Injection Risk: The skill is designed to analyze data from untrusted browser environments (DOM state, console logs, and network traffic). While this constitutes an attack surface, the behavior is intrinsic to the skill's purpose. \n * Ingestion points: Browser console logs, network payloads, and DOM transitions retrieved from the target website.\n * Boundary markers: Absent. The instructions do not define specific delimiters for separating untrusted browser data from agent instructions.\n * Capability inventory: The skill has permission to modify files within the workspace (workspace-write) to implement fixes.\n * Sanitization: Not mentioned; the skill relies on the agent's internal safety logic to process external content safely.
Audit Metadata
Risk Level
SAFE
Analyzed
May 12, 2026, 01:42 AM
Security Audit — agent-trust-hub — browser-debugger