paw-mkt-seo

Pass

Audited by Gen Agent Trust Hub on May 20, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches and installs the agent-browser utility from Vercel Labs' official GitHub repository, which is a trusted source.
  • [COMMAND_EXECUTION]: Utilizes shell commands to perform live SERP analysis, Core Web Vitals testing, and automated browser research sessions.
  • [DATA_EXFILTRATION]: Accesses browser profiles in the home directory (e.g., ~/.linkedin-profile) to facilitate authenticated marketing research on social platforms as part of its primary research purpose.
  • [PROMPT_INJECTION]: Contains a vulnerability surface for indirect prompt injection where user-supplied keywords are interpolated into shell commands without explicit sanitization.
  • Ingestion points: capability-research.md (keyword variables)
  • Boundary markers: Absent
  • Capability inventory: agent-browser automation, shell execution
  • Sanitization: None detected
Audit Metadata
Risk Level
SAFE
Analyzed
May 20, 2026, 10:38 AM
Security Audit — agent-trust-hub — paw-mkt-seo