browser-automation-framework
Warn
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill's primary function is to write custom Playwright scripts (JavaScript) to the
/tmpdirectory and execute them usingnode. It also provides an 'Inline Execution' feature that allows for the direct execution of arbitrary JavaScript code strings through a wrapper script. - [INDIRECT_PROMPT_INJECTION]: The skill has a significant attack surface for indirect prompt injection because it is designed to visit external URLs and process their content (e.g., extracting links, titles, and form data). Malicious content on a web page could attempt to manipulate the agent's logic during the script generation or interpretation phases.
- Ingestion points: Web page content (HTML, text, metadata), server discovery outputs, and link attributes.
- Boundary markers: No explicit boundary markers or instructions to ignore embedded commands in page content are provided in the skill instructions.
- Capability inventory: The skill possesses network access via a browser, file system write access to
/tmp, and the ability to execute shell commands and Node.js scripts. - Sanitization: There is no evidence of sanitization or validation of the data retrieved from web pages before it is used to inform agent actions.
- [COMMAND_EXECUTION]: The skill routinely executes shell commands to detect local development servers, run the
npm run setuproutine, and invoke the generated JavaScript automation scripts. - [DATA_EXFILTRATION]: The skill can capture screenshots and extract sensitive data from internal (localhost) and external websites. This data is stored in the
/tmpdirectory, which is a shared location, potentially exposing test artifacts or extracted secrets to other local processes.
Audit Metadata