skills/jswortz/my-skills/browser-use/Gen Agent Trust Hub

browser-use

Warn

Audited by Gen Agent Trust Hub on May 6, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/check_install.py uses subprocess.check_call to execute pip install browser-use. This allows the skill to modify the local environment by installing external packages at runtime without explicit user confirmation during the script execution.
  • [EXTERNAL_DOWNLOADS]: The skill is designed to download and install the browser-use Python package from the official Python Package Index (PyPI). While PyPI is a standard service, automated installation of third-party libraries at runtime increases the attack surface.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection (Category 8). Because the agent is instructed to process and act upon content from arbitrary external websites, a malicious webpage could contain hidden instructions that influence the agent's behavior.
  • Ingestion points: Web content processed by the Agent class in scripts/basic_automation.py and SKILL.md.
  • Boundary markers: None identified in the provided instructions to differentiate between user instructions and website content.
  • Capability inventory: The agent can navigate the web, click elements, fill forms, and potentially write to the local filesystem if the Controller.action example is implemented as shown in references/common_patterns.md.
  • Sanitization: No evidence of sanitization or filtering of website content before it is processed by the agent's LLM.
Audit Metadata
Risk Level
MEDIUM
Analyzed
May 6, 2026, 02:08 PM
Security Audit — agent-trust-hub — browser-use