skills/manaflow-ai/cmux/cmux-browser/Gen Agent Trust Hub

cmux-browser

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates interaction with and data extraction from arbitrary web pages, establishing an attack surface for indirect prompt injection where malicious instructions on a website could influence agent behavior.
  • Ingestion points: The agent ingests untrusted web content via the cmux browser snapshot --interactive command and get text/html verbs as documented in SKILL.md and references/snapshot-refs.md.
  • Boundary markers: While the skill uses an abstraction layer for interactions (using refs like e1, e2), there are no explicit delimiters or instructions to the agent to ignore embedded commands within the ingested page content.
  • Capability inventory: The skill possesses significant capabilities including writing browser state files (state save), performing network navigation (goto), and managing cookies/storage across various scripts.
  • Sanitization: Documentation in SKILL.md and references/surface-discovery.md advises redacting metadata and secrets from logs, but the skill does not implement programmatic sanitization of page content before processing.
  • [EXTERNAL_DOWNLOADS]: Documentation in SKILL.md provides commands to install or refresh the skill using the skills utility, which downloads content from the author's GitHub repository (manaflow-ai/cmux). This is a documented management function for the skill.
  • [CREDENTIALS_UNSAFE]: The skill handles sensitive authentication data such as browser cookies and session storage. It mitigates risk by providing clear security guidance in references/authentication.md, including the use of restricted file permissions (umask 077, chmod 600) for state files and recommending environment variables for credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 06:50 AM