pp-browserbase
Pass
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to download and install the
browserbase-pp-cliusingnpxfrom the@mvanhorn/printing-press-librarypackage andgo installfrom thegithub.com/mvanhorn/printing-press-libraryrepository. Both sources are associated with the recognized vendor.- [COMMAND_EXECUTION]: The skill is designed to execute shell commands through thebrowserbase-pp-clibinary, enabling the agent to create, list, and control browser sessions and associated metadata.- [DATA_EXFILTRATION]: The CLI tool includes a documented--deliver webhook:<url>feature which allows users to POST command outputs to external endpoints. This is a standard functionality for data routing and does not indicate malicious exfiltration.- [INDIRECT_PROMPT_INJECTION]: The skill provides an attack surface for indirect prompt injection as it ingests untrusted content from the web viafetchandwebsearchcommands. Ingestion points include external URLs and batch files. Boundary markers include formatting options like--format markdownand field selection via--select. Capabilities include network communication via the Browserbase API and the webhook feature. While the skill processes external content, it encourages minimizing the data surface returned to the agent context.
Audit Metadata