chrome-devtools

Warn

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The script scripts/evaluate.js accepts user input through the --script parameter and directly interprets it inside the browser environment using JavaScript's native eval() function via page.evaluate(). This creates a pathway for executing unrestricted JavaScript inside the automated browser session.
  • [COMMAND_EXECUTION]: The suite invokes external system executables via child_process.execFileSync inside scripts/screenshot.js to run the magick or convert binaries for automated screenshot compression. Although arguments are securely passed as an array to minimize shell injection vectors, the runtime still depends on invoking processes outside the Node environment.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 14, 2026, 10:09 PM
Security Audit — agent-trust-hub — chrome-devtools