agent-browser
Pass
Audited by Gen Agent Trust Hub on Mar 29, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides a legitimate set of instructions for web automation. All commands and examples are consistent with the stated purpose of browser testing and data extraction.
- [PROMPT_INJECTION]: The skill's functionality involves processing data from external web pages, which presents a surface for indirect prompt injection. This is an architectural risk inherent to browser-based agents.
- Ingestion points: Data enters the context through
snapshot,get text, andfindcommands inSKILL.md. - Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions for content retrieved from the web.
- Capability inventory: The skill includes interaction capabilities such as
click,fill, andopeninSKILL.md. - Sanitization: There is no evidence of sanitization or validation of external content prior to processing by the agent.
Audit Metadata