agent-browser-cli-control

Fail

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs users to install a CLI tool and a Chrome extension from an unverified third-party repository (sleepinginsummer/agent-browser-cli). These resources are not from a trusted vendor and have not undergone platform security reviews.
  • [CREDENTIALS_UNSAFE]: The agent-browser-cli cookies command allows the agent to extract full authentication cookies in plaintext from the user's browser. Since the tool targets existing, authenticated sessions, this presents a severe risk of session hijacking and unauthorized access to personal or financial accounts.
  • [COMMAND_EXECUTION]: The agent-browser-cli exec command provides a direct interface for executing arbitrary JavaScript within the context of any open browser tab. This capability can be abused to perform actions on behalf of the user, such as modifying form data or triggering transactions without explicit consent.
  • [DATA_EXFILTRATION]: The combination of browser content extraction (scan), cookie access (cookies), and screenshot capabilities (screenshot) provides a high-efficiency pipeline for exfiltrating sensitive data from authenticated web environments to external logs or endpoints.
  • [INDIRECT_PROMPT_INJECTION]: The skill is highly vulnerable to indirect prompt injection.
  • Ingestion points: The agent routinely ingests untrusted data from the web via the scan and active commands.
  • Boundary markers: There are no boundary markers or instructions to ignore embedded commands within scanned page content.
  • Capability inventory: The skill possesses powerful capabilities including arbitrary JavaScript execution (exec), cookie extraction, and file writing (screenshots).
  • Sanitization: There is no evidence of sanitization for the content retrieved from external web pages before it is processed by the agent.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 16, 2026, 09:00 PM
Security Audit — agent-trust-hub — agent-browser-cli-control