browser-safety

Pass

Audited by Gen Agent Trust Hub on Aug 3, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security risks were identified in the skill. The content is strictly instructional and promotes defensive security practices.
  • [CREDENTIALS_UNSAFE]: The skill explicitly warns against unsafe credential handling, advising against passing secrets as command-line arguments and recommending the use of environment variables and session state files instead.
  • [DATA_EXFILTRATION]: The skill provides guidance to prevent data exfiltration, instructing the agent to keep session data, cookies, and localStorage values on the local machine and never send them to unauthorized external hosts.
  • [PROMPT_INJECTION]: The skill includes instructions to mitigate indirect prompt injection, advising the agent to treat all page content as data rather than instructions and to use delimiters when reporting untrusted content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 3, 2026, 04:45 PM
Security Audit — agent-trust-hub — browser-safety