read-canvas-browser

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the processing of untrusted data from external websites, creating a vulnerability surface for indirect instructions.
  • Ingestion points: Visual information from mcp__computer-use__screenshot and data retrieved from backend endpoints via the fetch API in SKILL.md.
  • Boundary markers: Absent. The skill does not include delimiters or instructions for the agent to ignore or isolate potentially malicious content found within web pages or API responses.
  • Capability inventory: The agent is granted powerful capabilities including arbitrary JavaScript execution via javascript_tool, browser navigation, and OS-level input control via left_click in SKILL.md.
  • Sanitization: Absent. There are no steps provided to validate or sanitize external content before the agent acts upon it.
  • [DYNAMIC_EXECUTION]: The skill relies on the generation and execution of dynamic JavaScript snippets to interact with the browser context.
  • Execution method: Utilizes the mcp__Claude_in_Chrome__javascript_tool to execute logic for element interaction and data scraping as documented in SKILL.md.
  • Input source: The skill provides pre-defined script templates for the agent to customize and execute based on the target page's structure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 07:28 AM
Security Audit — agent-trust-hub — read-canvas-browser