browser-form-fill
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill executes an external command
npx -y @claude-flow/cli@latestto store templates. Fetching an unpinned version of an external package from a non-standard namespace at runtime introduces a supply chain risk where malicious updates could result in arbitrary code execution. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted web page elements to resolve selectors, creating a potential vector for indirect prompt injection.
- Ingestion points: Form input names, labels, and the accessible name tree gathered via the
browser_snapshottool inSKILL.md. - Boundary markers: Absent. There are no guidelines or formatting constraints specified to isolate form labels or content from the agent's instructions.
- Capability inventory: Includes executing bash commands (
npx), reading/writing files, and extensive browser control capabilities (open, fill, click, select, etc.). - Sanitization: Absent. The skill does not validate or sanitize the text strings retrieved from the web page accessibility tree prior to performing form-mapping or submission logic.
Audit Metadata