browser-automation

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to interact with and extract data from external websites, creating an attack surface for indirect prompt injection where malicious instructions on a web page could attempt to influence the agent's behavior.
  • Ingestion points: SecureBrowserAutomation.navigate and scrape_all_parallel functions in SKILL.md process content from arbitrary URLs.
  • Boundary markers: The skill does not demonstrate the use of explicit delimiters to encapsulate extracted content, although it mandates data redaction.
  • Capability inventory: The skill utilizes the Playwright library for network navigation, DOM manipulation, and script execution via the Chrome DevTools Protocol.
  • Sanitization: Implements robust sanitization via _validate_url (blocking banking/auth domains) and detect_credential (identifying tokens/keys via regex) in references/security-examples.md.
  • [COMMAND_EXECUTION]: The documentation includes standard shell commands for development workflows, such as running unit tests and checking code coverage.
  • Evidence: pytest tests/test_browser_automation.py and coverage commands in SKILL.md.
  • [DYNAMIC_EXECUTION]: The skill employs JavaScript injection into the browser context as a security control to ensure session isolation.
  • Evidence: The IsolatedBrowserSession class in references/advanced-patterns.md uses context.add_init_script to override and disable localStorage and sessionStorage.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:54 PM
Security Audit — agent-trust-hub — browser-automation