agent-browser
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill inherently exposes an attack surface for indirect prompt injection since it is designed to automate browser interactions, navigate websites, and extract page contents.
- Ingestion points: Web page content, DOM trees, accessibility trees, console logs, and network responses are ingested dynamically via commands like
agent-browser open,agent-browser snapshot, andagent-browser get textinSKILL.mdandreferences/commands.md. - Boundary markers: The skill explicitly documents robust boundary rules in
SKILL.md("Trust and Secret Handling" and "External Side Effects"), stating that all non-local page data must be treated as untrusted, and instructions found inside web pages must be ignored. - Capability inventory: The agent has capabilities to execute local commands (
agent-browser), interact with elements (click,fill,upload), manipulate browser state (cookies set,storage local set), and evaluate JavaScript code within the context of the page (agent-browser eval). - Sanitization: Explicit input sanitization or structural isolation instructions are not fully implemented at the technical layout layer, though clear prompt engineering boundaries are instructed to limit adherence to malicious text contained in page DOMs.
- [COMMAND_EXECUTION]: The skill relies extensively on executing the local
agent-browserCLI binary throughBashconfigurations defined in theallowed-toolssection ofSKILL.md. This tool usage is essential for the primary browser automation purpose.
Audit Metadata