browser

Pass

Audited by Gen Agent Trust Hub on Mar 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for using the 'validate' operator, which evaluates Python expressions at runtime to facilitate complex assertions.
  • [COMMAND_EXECUTION]: The skill documents keywords like 'Evaluate JavaScript' and 'Execute JavaScript' that allow for the execution of arbitrary scripts within the browser session.
  • [DATA_EXFILTRATION]: The skill handles sensitive authentication data, including cookies and local storage state, and provides functionality to save these sessions to local files.
  • [PROMPT_INJECTION]: The skill creates an attack surface for indirect prompt injection by fetching content from web pages and processing it through powerful keywords like 'validate' without explicit sanitization or boundary markers.
  • [DATA_EXFILTRATION]: The skill utilizes the Robot Framework 'OperatingSystem' library to perform local file system operations, such as creating and checking for the existence of files.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 19, 2026, 09:45 AM