super-browser
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection.
- Ingestion points: Untrusted data enters the agent context through the
navigateandsnapshotcommands as specified in SKILL.md. - Boundary markers: The instructions do not define boundary markers or clear directives for the agent to ignore instructions contained within the external web content it retrieves.
- Capability inventory: The skill allows for browser-level interactions including
click,type,navigate, and session/profile management, which could be leveraged if the agent follows instructions from an external source. - Sanitization: There is no evidence of sanitization or filtering of external content before it is processed by the agent.
Audit Metadata