chrome-devtools

Pass

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references the chrome-devtools-mcp package, which is part of the official Chrome DevTools ecosystem on GitHub.- [COMMAND_EXECUTION]: Implements browser automation tools such as click, fill, and navigate_page to interact with web content.- [REMOTE_CODE_EXECUTION]: Includes an evaluate_script capability that allows the agent to execute JavaScript within the browser context for data extraction and page manipulation.- [PROMPT_INJECTION]: The skill processes external web content which creates an indirect prompt injection surface.
  • Ingestion points: take_snapshot and evaluate_script in SKILL.md.
  • Boundary markers: Not present.
  • Capability inventory: click, fill, evaluate_script, and navigate_page in SKILL.md.
  • Sanitization: Not present.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 29, 2026, 08:52 AM