browser-automation-orchestrator
Warn
Audited by Gen Agent Trust Hub on Jun 21, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Dynamic Instruction Loading. The skill instructs the agent to dynamically load additional instruction sets from the local filesystem using a computed path (~/.agents/skill-clusters/skills//SKILL.md) based on the task routing.
- [COMMAND_EXECUTION]: Local Tool and Script Invocation. The skill facilitates the execution of various local automation tools and scripts, including the peekaboo macOS UI CLI, tmux for interactive TTY management, and Python-based Playwright test runners (scripts/with_server.py).
- [PROMPT_INJECTION]: Indirect Injection Surface. The skill is designed to ingest and process untrusted data from external sources, such as web page DOM content, browser console logs, and UI accessibility metadata, which could contain malicious instructions. * Ingestion points: Web page content, network/console logs, and screen/accessibility snapshots. * Boundary markers: None present. * Capability inventory: File system access, local CLI execution (tmux, peekaboo), and script execution. * Sanitization: No sanitization or validation of ingested UI/web data is specified.
Audit Metadata