agent-browser

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs the 'agent-browser' package globally using npm. This package is the official tool required for the skill's operation and is provided by the vendor 'supatest-ai'.
  • [COMMAND_EXECUTION]: The skill utilizes the 'agent-browser' CLI to perform web automation tasks such as opening URLs, clicking elements, and taking snapshots. It also uses the CLI to dynamically retrieve core instruction sets.
  • [PROMPT_INJECTION]: The skill exposes a surface for indirect prompt injection by processing content from external websites. Ingestion points: The agent ingests untrusted data through page snapshots and scraping actions. Boundary markers: No explicit delimiters are specified to separate external content from instructions in the provided generic workflow. Capability inventory: The agent has the ability to navigate the web, manipulate page state, and execute local CLI commands. Sanitization: The skill does not perform explicit sanitization or filtering of data scraped from web pages.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 10:29 AM
Security Audit — agent-trust-hub — agent-browser