chrome-devtools
Pass
Audited by Gen Agent Trust Hub on Mar 29, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references the
chrome-devtools-mcppackage, which is part of the official Chrome DevTools ecosystem on GitHub.- [COMMAND_EXECUTION]: Implements browser automation tools such asclick,fill, andnavigate_pageto interact with web content.- [REMOTE_CODE_EXECUTION]: Includes anevaluate_scriptcapability that allows the agent to execute JavaScript within the browser context for data extraction and page manipulation.- [PROMPT_INJECTION]: The skill processes external web content which creates an indirect prompt injection surface. - Ingestion points:
take_snapshotandevaluate_scriptin SKILL.md. - Boundary markers: Not present.
- Capability inventory:
click,fill,evaluate_script, andnavigate_pagein SKILL.md. - Sanitization: Not present.
Audit Metadata