competition-browser-persistence

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill is purely instructional and focused on analyzing web browser state for security challenges within a controlled sandbox environment. No malicious patterns or security violations were detected in the instructions or references.
  • [NO_CODE]: The skill does not include any scripts, executables, or code files; it consists entirely of instructional Markdown content and configuration metadata.
  • [PROMPT_INJECTION]: Evaluated for potential indirect prompt injection surface. The skill is designed to ingest and analyze untrusted data from browser persistence layers.
  • Ingestion points: SKILL.md (Step 1) and references/browser-persistence.md (Surfaces To Check) specify reading cookies, localStorage, IndexedDB, and Cache Storage data from external origins.
  • Boundary markers: No specific boundary markers or 'ignore embedded instructions' warnings are provided for the stateful data.
  • Capability inventory: The skill is instructional and does not restrict specific tools in the frontmatter, though the workflow implies use of browser inspection capabilities.
  • Sanitization: No explicit sanitization or validation of the stored state content is mentioned. This risk is inherent to the skill's primary purpose of analyzing external web environments and is addressed by standard agent guardrails.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 09:26 AM
Security Audit — agent-trust-hub — competition-browser-persistence