chrome-devtools
Warn
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]: The script
scripts/evaluate.jsaccepts user input through the--scriptparameter and directly interprets it inside the browser environment using JavaScript's nativeeval()function viapage.evaluate(). This creates a pathway for executing unrestricted JavaScript inside the automated browser session. - [COMMAND_EXECUTION]: The suite invokes external system executables via
child_process.execFileSyncinsidescripts/screenshot.jsto run themagickorconvertbinaries for automated screenshot compression. Although arguments are securely passed as an array to minimize shell injection vectors, the runtime still depends on invoking processes outside the Node environment.
Audit Metadata