browser-javascript-profiling

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEDATA_EXFILTRATIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill documents that performance traces and heap snapshots can capture sensitive information, including URLs, tokens, and DOM text.
  • Evidence: The 'Artifacts, privacy, and production safety' section explicitly warns that traces can contain credentials, personal data, and internal metadata.
  • Mitigation: The skill advises using synthetic data, test accounts, and proper redaction before sharing or saving artifacts.
  • [DYNAMIC_EXECUTION]: The skill provides a JavaScript boilerplate intended for execution via the agent's browser tool using the browser.run capability.
  • Evidence: The 'Agent-executable capture with the Browser tool' section includes a code block that utilizes page.createCDPSession() to interact with the Chrome DevTools Protocol (CDP).
  • [COMMAND_EXECUTION]: The provided scripts execute specific browser-level commands to start and stop performance tracing.
  • Evidence: The script uses client.send('Tracing.start', ...) and client.send('IO.read', ...) to programmatically control the browser and retrieve performance data.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 02:00 AM
Security Audit — agent-trust-hub — browser-javascript-profiling