browser-use
Warn
Audited by Gen Agent Trust Hub on May 6, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/check_install.pyusessubprocess.check_callto executepip install browser-use. This allows the skill to modify the local environment by installing external packages at runtime without explicit user confirmation during the script execution. - [EXTERNAL_DOWNLOADS]: The skill is designed to download and install the
browser-usePython package from the official Python Package Index (PyPI). While PyPI is a standard service, automated installation of third-party libraries at runtime increases the attack surface. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection (Category 8). Because the agent is instructed to process and act upon content from arbitrary external websites, a malicious webpage could contain hidden instructions that influence the agent's behavior.
- Ingestion points: Web content processed by the
Agentclass inscripts/basic_automation.pyandSKILL.md. - Boundary markers: None identified in the provided instructions to differentiate between user instructions and website content.
- Capability inventory: The agent can navigate the web, click elements, fill forms, and potentially write to the local filesystem if the
Controller.actionexample is implemented as shown inreferences/common_patterns.md. - Sanitization: No evidence of sanitization or filtering of website content before it is processed by the agent's LLM.
Audit Metadata