browser
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The
scripts/start.cjsscript utilizeschild_process.spawnto launch a Chrome browser instance with remote debugging enabled. It targets standard executable paths across macOS, Linux, and Windows systems.- [DYNAMIC_EXECUTION]: Thescripts/eval.cjsandscripts/pick.cjsscripts use the Chrome DevTools ProtocolRuntime.evaluatemethod to execute arbitrary JavaScript strings provided via command-line arguments within the browser context.- [INDIRECT_PROMPT_INJECTION]: The skill exposes the agent to indirect prompt injection by design, as it allows navigation to and data extraction from external websites. An attacker could embed malicious instructions in a webpage to manipulate the agent via its browser control tools. 1. Ingestion points: Webpage navigation (nav.cjs) and data extraction via element selection or script evaluation (pick.cjs,eval.cjs). 2. Boundary markers: None present; the skill does not use delimiters to isolate untrusted web content from its instructions. 3. Capability inventory: The skill can spawn processes, execute arbitrary JS in the browser, capture screenshots, and write to the local filesystem (temporary directory). 4. Sanitization: None detected; the skill passes raw strings to the browser's execution engine without validation.- [EXTERNAL_DOWNLOADS]: The skill relies on thewslibrary for WebSocket communication. Thepackage-lock.jsonfiles indicate these dependencies are resolved fromregistry.npmmirror.com, a third-party registry mirror.
Audit Metadata