agent-browser

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill inherently exposes an attack surface for indirect prompt injection since it is designed to automate browser interactions, navigate websites, and extract page contents.
  • Ingestion points: Web page content, DOM trees, accessibility trees, console logs, and network responses are ingested dynamically via commands like agent-browser open, agent-browser snapshot, and agent-browser get text in SKILL.md and references/commands.md.
  • Boundary markers: The skill explicitly documents robust boundary rules in SKILL.md ("Trust and Secret Handling" and "External Side Effects"), stating that all non-local page data must be treated as untrusted, and instructions found inside web pages must be ignored.
  • Capability inventory: The agent has capabilities to execute local commands (agent-browser), interact with elements (click, fill, upload), manipulate browser state (cookies set, storage local set), and evaluate JavaScript code within the context of the page (agent-browser eval).
  • Sanitization: Explicit input sanitization or structural isolation instructions are not fully implemented at the technical layout layer, though clear prompt engineering boundaries are instructed to limit adherence to malicious text contained in page DOMs.
  • [COMMAND_EXECUTION]: The skill relies extensively on executing the local agent-browser CLI binary through Bash configurations defined in the allowed-tools section of SKILL.md. This tool usage is essential for the primary browser automation purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:41 PM
Security Audit — agent-trust-hub — agent-browser