eyes
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [Prompt Injection] (LOW): The skill is vulnerable to indirect prompt injection because it processes content from external websites.\n- Ingestion points:
browser_navigate,browser_snapshot, andbrowser_console_messagesinSKILL.mdbring external data into the agent's context.\n- Boundary markers: Absent; there are no instructions to ignore embedded commands in the web data.\n- Capability inventory: High; the skill uses Playwright tools for navigation, interaction, and debugging.\n- Sanitization: Absent; web content is processed without filtering.\n- [External Downloads] (SAFE): Thebrowser_installtool is used for standard Playwright environment setup.
Audit Metadata