browser-testing-with-devtools
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill identifies that all data retrieved from a browser (DOM, console, network) is untrusted. It explicitly instructs the agent to treat this content as data rather than instructions, providing a robust defense against indirect prompt injection. It also mandates boundary markers and user confirmation for navigating to extracted URLs.
- [EXTERNAL_DOWNLOADS]: The skill configuration uses the
@anthropic/chrome-devtools-mcppackage via npx. This is a well-known package from a trusted organization. - [DYNAMIC_EXECUTION]: While the skill utilizes a JavaScript execution tool, it imposes strict security constraints: prohibiting credential access (cookies, localStorage), restricting external network requests from the page context, and requiring user confirmation for any state-modifying actions.
- [PROMPT_INJECTION]: Automated detectors flagged a potential prompt injection attempt. However, analysis shows this text is a defensive instruction to the agent to ignore and flag injection attempts found within browser content, which is a security best practice.
Audit Metadata