dashboard-forge

Fail

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: HIGHDATA_EXFILTRATIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONCREDENTIALS_UNSAFEPRIVILEGE_ESCALATIONEXTERNAL_DOWNLOADS
Full Analysis
  • [DATA_EXFILTRATION]: The skill describes techniques for accessing and copying sensitive browser session data, including 'Cookies' and 'Local State' files from the user's profile directory (~/Library/Application Support/Google/Chrome), which facilitates session hijacking.
  • [COMMAND_EXECUTION]: It employs AppleScript to drive the host's Google Chrome application, providing full control over the user's active browser windows and tabs.
  • [DYNAMIC_EXECUTION]: The skill uses 'execute javascript' via AppleScript and 'page.evaluate' in Playwright to run dynamically generated code within browser contexts to extract secrets and automate interactions.
  • [CREDENTIALS_UNSAFE]: It details methods for intercepting authentication tokens from network traffic and extracting raw secrets directly from the browser's DOM.
  • [PRIVILEGE_ESCALATION]: The instructions include logic for bypassing or automating re-authentication prompts, such as GitHub's 'sudo mode', to perform privileged operations without user intervention.
  • [EXTERNAL_DOWNLOADS]: Mentions the installation of external packages like 'dfindexeddb' and 'python-snappy' for processing browser database files.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 28, 2026, 12:41 PM
Security Audit — agent-trust-hub — dashboard-forge