browser
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill relies on executing shell commands through the
agent-browserCLI andnpx @claude-flow/cli. These commands facilitate browser control, session management, and hooks for the agent workflow. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and act upon data from external, untrusted web pages, creating a surface for indirect prompt injection attacks.
- Ingestion points: Tools such as
browser/snapshot,get text, andget html(defined inSKILL.md) ingest raw DOM and accessibility tree data into the agent's context. - Boundary markers: None. The skill does not implement delimiters or specific instructions to the agent to ignore potentially malicious content embedded in the target websites.
- Capability inventory: The skill provides extensive capabilities including navigation (
open), interaction (click,fill,type), session state management (state save/load), and local command execution vianpxhooks. - Sanitization: None. The skill processes and passes data directly from the browser to the agent without filtering or validation of the content's intent.
Audit Metadata