skills/oldwinter/skills/browser/Gen Agent Trust Hub

browser

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The scripts/start.cjs script utilizes child_process.spawn to launch a Chrome browser instance with remote debugging enabled. It targets standard executable paths across macOS, Linux, and Windows systems.- [DYNAMIC_EXECUTION]: The scripts/eval.cjs and scripts/pick.cjs scripts use the Chrome DevTools Protocol Runtime.evaluate method to execute arbitrary JavaScript strings provided via command-line arguments within the browser context.- [INDIRECT_PROMPT_INJECTION]: The skill exposes the agent to indirect prompt injection by design, as it allows navigation to and data extraction from external websites. An attacker could embed malicious instructions in a webpage to manipulate the agent via its browser control tools. 1. Ingestion points: Webpage navigation (nav.cjs) and data extraction via element selection or script evaluation (pick.cjs, eval.cjs). 2. Boundary markers: None present; the skill does not use delimiters to isolate untrusted web content from its instructions. 3. Capability inventory: The skill can spawn processes, execute arbitrary JS in the browser, capture screenshots, and write to the local filesystem (temporary directory). 4. Sanitization: None detected; the skill passes raw strings to the browser's execution engine without validation.- [EXTERNAL_DOWNLOADS]: The skill relies on the ws library for WebSocket communication. The package-lock.json files indicate these dependencies are resolved from registry.npmmirror.com, a third-party registry mirror.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 05:21 AM
Security Audit — agent-trust-hub — browser