agent-browser-2

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructions involve installing the agent-browser package from the NPM registry and using the tool to download browser binaries (Chromium) and system dependencies.
  • [COMMAND_EXECUTION]: The skill extensively uses the agent-browser CLI to perform automated browser actions such as clicking, typing, and managing network routes.
  • [INDIRECT_PROMPT_INJECTION]: The skill enables the agent to navigate to external URLs and capture accessibility tree snapshots, which introduces a vulnerability to indirect prompt injection from untrusted web content.
  • Ingestion points: Browser snapshots and element text extraction (e.g., agent-browser snapshot, agent-browser get text).
  • Boundary markers: The skill encourages the use of JSON output (--json), which provides a structured format but does not prevent the agent from interpreting instructions embedded within the text fields of the JSON.
  • Capability inventory: Includes the ability to interact with web elements, manage cookies and local storage, and execute JavaScript within the browser context (agent-browser wait --fn).
  • Sanitization: No explicit sanitization of the retrieved web content is documented in the skill instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 10:34 AM
Security Audit — agent-trust-hub — agent-browser-2