browser
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted web content which creates a surface for indirect prompt injection attacks.
- Ingestion points: The skill ingests external data via
agent-browser snapshot,agent-browser get text, andagent-browser get html(SKILL.md). - Boundary markers: The instructions do not define boundary markers or delimiters to separate untrusted web content from agent instructions.
- Capability inventory: The agent has the capability to perform actions based on processed data using
agent-browser click,agent-browser fill, andagent-browser open(SKILL.md). - Sanitization: There is no evidence of sanitization or filtering of the content retrieved from web pages.
- [EXTERNAL_DOWNLOADS]: The skill utilizes
npx @claude-flow/cliin its examples for memory and hook integration, which involves downloading and executing code from the npm registry. - [COMMAND_EXECUTION]: The skill's primary functionality is built upon executing shell commands through the
agent-browserCLI tool and the@claude-flow/clivia npx. - [DATA_EXFILTRATION]: The skill features session management capabilities, specifically
agent-browser state save auth.jsonandagent-browser state load auth.json. These files typically contain sensitive authentication tokens and cookies. While used for legitimate session persistence, they represent a potential data exposure risk if the environment is compromised.
Audit Metadata