browser-test
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external websites, creating a surface for indirect prompt injection attacks.
- Ingestion points: Web content is ingested via tools such as
browser_get-text,browser_get-value,browser_get-title,browser_get-url, andbrowser_evalas described in SKILL.md. - Boundary markers: The instructions recommend using
aidefence_is_safeto validate content, which acts as a partial boundary, though it does not eliminate the risk of sophisticated injections. - Capability inventory: The skill has access to sensitive tools including
Bash,Write, and variousbrowser_*interaction tools specified in the frontmatter. - Sanitization: The skill explicitly instructs the agent to pass validation outputs through the
aidefence_is_safetool and to redact strings returned frombrowser_evalbefore logging. - [DYNAMIC_EXECUTION]: The skill utilizes dynamic JavaScript execution within the browser environment.
- Evidence: The instructions in SKILL.md suggest using
browser_evalfor custom JavaScript assertions. - Mitigation: The skill includes a instruction to redact and sanitize returned strings via the
aidefence_is_safegate. - [COMMAND_EXECUTION]: The skill environment is configured with shell access.
- Evidence: The YAML frontmatter includes
Bashin theallowed-toolslist, providing the agent with the capability to execute system commands if prompted.
Audit Metadata