agentic-browser
Fail
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: CRITICALREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- Unverifiable Dependencies & Remote Code Execution (CRITICAL): The skill documentation recommends an insecure installation method for its CLI tool.
- Evidence: The command
curl -fsSL https://cli.inference.sh | shdownloads and executes a script from an untrusted domain without any cryptographic verification or user review, allowing the remote server to execute arbitrary code with the user's shell privileges. - Dynamic Execution (HIGH): The skill provides an
executefunction that allows the agent to run arbitrary JavaScript code within the browser context. - Evidence: In
SKILL.md, theexecutefunction accepts acodestring that is executed via the browser automation backend. This could be used to bypass security policies or interact with sensitive page data if the agent is manipulated. - Indirect Prompt Injection (LOW): The skill is highly vulnerable to indirect prompt injection due to its core browsing capabilities.
- Ingestion points: The
openandsnapshotfunctions allow the agent to ingest arbitrary content from any URL. - Boundary markers: Absent. There are no instructions or delimiters defined to prevent the agent from following commands embedded in the web content.
- Capability inventory: The skill has significant capabilities including
Bash(infsh *)tool access, fileuploadactions, and arbitrary JavaScriptexecutecalls. - Sanitization: Absent. The skill does not provide any mechanism to filter or sanitize content retrieved from the web before the agent processes it.
- Data Exposure & Exfiltration (MEDIUM): The skill facilitates the handling of sensitive data such as proxy credentials and local files.
- Evidence: Support for
proxy_username,proxy_password, and anuploadaction for file paths in tool inputs increases the risk of exfiltrating sensitive local data or exposing credentials in logs.
Recommendations
- HIGH: Downloads and executes remote code from: https://cli.inference.sh - DO NOT USE without thorough review
- AI detected serious security threats
Audit Metadata