agent-browser

Pass

Audited by Gen Agent Trust Hub on May 8, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • Dependency Management: The skill recommends installing a global NPM package to provide its core functionality. This is a routine procedure for developer tools but involves executing scripts from a package registry.
  • Dynamic Content Loading: The CLI includes a mechanism to fetch workflow instructions and templates at runtime. This practice ensures that the AI agent always operates with documentation that matches the software version, though it involves fetching external instructions during the session.
  • Indirect Prompt Injection Surface: As a tool designed for web and desktop app automation, the skill ingests data from external sources such as live websites and user interfaces. This creates a potential surface where untrusted content could contain instructions intended to influence the agent's behavior.
  • Ingestion points: Reads accessibility trees and page snapshots from any URL the agent navigates to.
  • Boundary markers: Not explicitly defined in this discovery stub.
  • Capability inventory: Provides capabilities for clicking, form filling, and running browser-based tasks via Bash.
  • Sanitization: Relies on the underlying browser CDP and the agent's internal filtering for safety.
  • Credential Management: The tool mentions an authentication vault for session persistence. This is used to manage login states for automated tasks across different sessions.
Audit Metadata
Risk Level
SAFE
Analyzed
May 8, 2026, 08:32 AM
Security Audit — agent-trust-hub — agent-browser