browser-javascript-profiling
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEDATA_EXFILTRATIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [DATA_EXFILTRATION]: The skill documents that performance traces and heap snapshots can capture sensitive information, including URLs, tokens, and DOM text.
- Evidence: The 'Artifacts, privacy, and production safety' section explicitly warns that traces can contain credentials, personal data, and internal metadata.
- Mitigation: The skill advises using synthetic data, test accounts, and proper redaction before sharing or saving artifacts.
- [DYNAMIC_EXECUTION]: The skill provides a JavaScript boilerplate intended for execution via the agent's browser tool using the
browser.runcapability. - Evidence: The 'Agent-executable capture with the Browser tool' section includes a code block that utilizes
page.createCDPSession()to interact with the Chrome DevTools Protocol (CDP). - [COMMAND_EXECUTION]: The provided scripts execute specific browser-level commands to start and stop performance tracing.
- Evidence: The script uses
client.send('Tracing.start', ...)andclient.send('IO.read', ...)to programmatically control the browser and retrieve performance data.
Audit Metadata