browser-use

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The file mcporter-config.md exposes a hardcoded absolute path to a specific user's Chrome profile directory, which contains sensitive data such as cookies, history, and stored credentials.
  • Evidence: The configuration example explicitly uses /Users/steipete/Library/Application Support/Google/Chrome as the userDataDir.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from web pages and has the capability to interact with the environment through browser control commands, creating an attack surface for instructions embedded in web content.
  • Ingestion points: SKILL.md instructions for take_snapshot, list_pages, and evaluate_script allow external data to enter the agent's context.
  • Capability inventory: The skill can perform actions like click, fill, evaluate_script, and navigate_page based on agent decisions.
  • Boundary markers: The instructions describe transport boundaries (relay-only routing), but do not specify natural language delimiters for data processed by the agent.
  • Sanitization: Instructions mention keeping secrets out of DOM snapshots and tool outputs, but do not describe specific sanitization logic for incoming data.
  • [EXTERNAL_DOWNLOADS]: The configuration guide instructs the user to use npx to fetch and execute a package from the NPM registry at runtime.
  • Evidence: mcporter-config.md includes commands like npx -y chrome-devtools-mcp.
  • [COMMAND_EXECUTION]: The skill relies on shell command execution to interface with the browser control daemon and extension tools.
  • Evidence: Multiple instances of mcporter call ... and openclaw browser extension ... throughout SKILL.md.
  • [DYNAMIC_EXECUTION]: The skill uses evaluate_script to execute arbitrary JavaScript within the context of the user's browser tabs.
  • Evidence: SKILL.md provides examples of calling chrome-devtools.evaluate_script to run functions on active pages.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 03:17 PM
Security Audit — agent-trust-hub — browser-use