browse-geo
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted content from various AI-driven search engines (Google, Perplexity, and ChatGPT). This external data constitutes an attack surface where malicious content on a web page could attempt to influence the agent's logic during the analysis and reporting phase. Ingestion points: Web content and AI summaries retrieved via browse snapshot and browse text commands in SKILL.md. Boundary markers: The instructions do not define clear delimiters or constraints to prevent the agent from obeying instructions embedded in the retrieved text. Capability inventory: The skill utilizes the Bash tool to execute browse CLI commands, providing a significant capability for environment interaction. Sanitization: There is no mention of sanitizing or validating the ingested content before it is processed by the agent.
Audit Metadata