chrome-browser
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external web pages, creating a surface for instructions embedded in those pages to influence the agent's behavior.
- Ingestion points: The skill reads page structure and text via
mcp__claude-in-chrome__read_page,mcp__chrome-devtools__take_snapshot, andmcp__claude-in-chrome__get_page_textas documented inSKILL.md. - Boundary markers: Absent; the instructions do not specify using delimiters or warnings to ignore instructions embedded within the processed web content.
- Capability inventory: The skill possesses the capability to execute JavaScript in the browser (
mcp__chrome-devtools__evaluate_script), perform network operations, and write files (performance traces and GIF exports) as seen inSKILL.md. It also spawns a local subprocess inscripts/main.cjs. - Sanitization: Absent; there is no mention of filtering, escaping, or validating the content retrieved from web pages before processing.
- [DYNAMIC_EXECUTION]: The skill includes tools that allow for the dynamic execution of JavaScript code within the browser context.
- Evidence:
SKILL.mddocuments the use ofmcp__chrome-devtools__evaluate_scriptandmcp__claude-in-chrome__javascript_toolfor custom checks and page interaction. - [COMMAND_EXECUTION]: The skill's primary entry point executes a local tool file via a subprocess.
- Evidence:
scripts/main.cjsuseschild_process.spawnto execute a local JavaScript file located at.claude/tools/chrome-browser/chrome-browser.cjs. - [EXTERNAL_DOWNLOADS]: The documentation points to external installation requirements from well-known and trusted sources.
- Evidence:
SKILL.mdreferences the official Google Chrome download site and the Claude-in-Chrome extension on the Chrome Web Store.
Audit Metadata