control-browser

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from third-party web pages via snapshots and screenshots, creating a surface for indirect prompt injection where malicious content could attempt to influence the agent's behavior.
  • Ingestion points: Web content is ingested through page_snapshot and page_screenshot tools as described in SKILL.md and docs/api-use-behavior.md.
  • Boundary markers: docs/browser-safety.md contains explicit instructions to treat all page content as data, not instructions, and to ignore any commands found within pages or emails.
  • Capability inventory: The skill has high-privilege access to the user's authenticated browser session, including navigation, form submission, and tab management.
  • Sanitization: The skill implements a robust confirmation gate for any sensitive or irreversible actions (e.g., purchases, form submissions, sending messages) as detailed in docs/confirmations.md, requiring explicit user consent before execution.
  • [PROMPT_INJECTION]: Static analysis identified potential concealment instructions; however, review of the documentation shows these are technical descriptions of background processing rather than malicious intent. The skill mandates that the agent narrate background actions to the user to maintain visibility into automated processes and mitigate the risk of hidden actions.
  • [DATA_EXFILTRATION]: The skill includes strong defensive instructions against data exfiltration. SKILL.md and docs/browser-safety.md forbid the agent from accessing local sensitive files (like SSH keys or environment variables) and from harvesting the user's browser history, cookies, or saved credentials without a direct task-related need.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:45 AM
Security Audit — agent-trust-hub — control-browser