pp-browserbase

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to download and install the browserbase-pp-cli using npx from the @mvanhorn/printing-press-library package and go install from the github.com/mvanhorn/printing-press-library repository. Both sources are associated with the recognized vendor.- [COMMAND_EXECUTION]: The skill is designed to execute shell commands through the browserbase-pp-cli binary, enabling the agent to create, list, and control browser sessions and associated metadata.- [DATA_EXFILTRATION]: The CLI tool includes a documented --deliver webhook:<url> feature which allows users to POST command outputs to external endpoints. This is a standard functionality for data routing and does not indicate malicious exfiltration.- [INDIRECT_PROMPT_INJECTION]: The skill provides an attack surface for indirect prompt injection as it ingests untrusted content from the web via fetch and websearch commands. Ingestion points include external URLs and batch files. Boundary markers include formatting options like --format markdown and field selection via --select. Capabilities include network communication via the Browserbase API and the webhook feature. While the skill processes external content, it encourages minimizing the data surface returned to the agent context.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 12:38 PM
Security Audit — agent-trust-hub — pp-browserbase