browser
Pass
Audited by Gen Agent Trust Hub on Mar 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for using the 'validate' operator, which evaluates Python expressions at runtime to facilitate complex assertions.
- [COMMAND_EXECUTION]: The skill documents keywords like 'Evaluate JavaScript' and 'Execute JavaScript' that allow for the execution of arbitrary scripts within the browser session.
- [DATA_EXFILTRATION]: The skill handles sensitive authentication data, including cookies and local storage state, and provides functionality to save these sessions to local files.
- [PROMPT_INJECTION]: The skill creates an attack surface for indirect prompt injection by fetching content from web pages and processing it through powerful keywords like 'validate' without explicit sanitization or boundary markers.
- [DATA_EXFILTRATION]: The skill utilizes the Robot Framework 'OperatingSystem' library to perform local file system operations, such as creating and checking for the existence of files.
Audit Metadata