cmux-browser
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates interaction with and data extraction from arbitrary web pages, establishing an attack surface for indirect prompt injection where malicious instructions on a website could influence agent behavior.
- Ingestion points: The agent ingests untrusted web content via the
cmux browser snapshot --interactivecommand andget text/htmlverbs as documented inSKILL.mdandreferences/snapshot-refs.md. - Boundary markers: While the skill uses an abstraction layer for interactions (using refs like
e1,e2), there are no explicit delimiters or instructions to the agent to ignore embedded commands within the ingested page content. - Capability inventory: The skill possesses significant capabilities including writing browser state files (
state save), performing network navigation (goto), and managing cookies/storage across various scripts. - Sanitization: Documentation in
SKILL.mdandreferences/surface-discovery.mdadvises redacting metadata and secrets from logs, but the skill does not implement programmatic sanitization of page content before processing. - [EXTERNAL_DOWNLOADS]: Documentation in
SKILL.mdprovides commands to install or refresh the skill using theskillsutility, which downloads content from the author's GitHub repository (manaflow-ai/cmux). This is a documented management function for the skill. - [CREDENTIALS_UNSAFE]: The skill handles sensitive authentication data such as browser cookies and session storage. It mitigates risk by providing clear security guidance in
references/authentication.md, including the use of restricted file permissions (umask 077,chmod 600) for state files and recommending environment variables for credentials.
Audit Metadata