browser-automation
Pass
Audited by Gen Agent Trust Hub on Apr 8, 2026
Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
- [NO_CODE]: The provided files consist of Markdown documentation and structural templates. No source code, scripts, or package manifest files (e.g., package.json, requirements.txt) are included.
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface. 1. Ingestion points: The skill defines capabilities for web-scraping and agentic browser interactions (SKILL.md), which involve reading data from untrusted external websites. 2. Boundary markers: No delimiters or specific instructions for isolating external content from system prompts are provided in the patterns. 3. Capability inventory: The skill references Playwright and Puppeteer, which are powerful browser automation tools with full network and potential file system access. 4. Sanitization: No sanitization or validation logic is discussed for managing untrusted inputs from the browser environment.
Audit Metadata