browser-testing-with-devtools

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies that all data retrieved from a browser (DOM, console, network) is untrusted. It explicitly instructs the agent to treat this content as data rather than instructions, providing a robust defense against indirect prompt injection. It also mandates boundary markers and user confirmation for navigating to extracted URLs.
  • [EXTERNAL_DOWNLOADS]: The skill configuration uses the @anthropic/chrome-devtools-mcp package via npx. This is a well-known package from a trusted organization.
  • [DYNAMIC_EXECUTION]: While the skill utilizes a JavaScript execution tool, it imposes strict security constraints: prohibiting credential access (cookies, localStorage), restricting external network requests from the page context, and requiring user confirmation for any state-modifying actions.
  • [PROMPT_INJECTION]: Automated detectors flagged a potential prompt injection attempt. However, analysis shows this text is a defensive instruction to the agent to ignore and flag injection attempts found within browser content, which is a security best practice.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 10:41 AM
Security Audit — agent-trust-hub — browser-testing-with-devtools