browser-use

Warn

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill allows the execution of arbitrary Python code through the browser-use python command and JavaScript via browser-use eval.
  • [CREDENTIALS_UNSAFE]: The skill provides functions to export browser cookies to local files and sync entire user profiles to the cloud, which includes sensitive session tokens and authentication data.
  • [EXTERNAL_DOWNLOADS]: The skill references components from the browser-use GitHub repository and uses Cloudflare services to establish tunnels for local development servers.
  • [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection by processing data from untrusted websites. Ingestion points: Content retrieved from web pages via navigation and state commands in SKILL.md. Boundary markers: No explicit delimiters or warnings to ignore embedded instructions are used. Capability inventory: The skill has access to shell commands, Python execution, and cookie management tools. Sanitization: No sanitization or filtering of external content is documented.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 15, 2026, 12:52 PM
Security Audit — agent-trust-hub — browser-use