chrome-bridge-automation

Pass

Audited by Gen Agent Trust Hub on Mar 25, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses npx @midscene/web@1 to fetch and execute the Midscene automation tool from the NPM registry at runtime. This is an intended component of the skill's infrastructure and originates from the vendor.\n- [COMMAND_EXECUTION]: Shell commands are used to invoke the Midscene CLI for browser interaction and screenshot capture.\n- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted web content via visual grounding to make operational decisions.\n
  • Ingestion points: Page content is ingested through screenshots and processed by the act command as specified in SKILL.md.\n
  • Boundary markers: No specific delimiters or instructions are used to distinguish external web content from the agent's internal instructions.\n
  • Capability inventory: The skill possesses the Bash tool and has control over the user's live browser session, including logged-in states.\n
  • Sanitization: Visual data and text from web pages are not sanitized or filtered before interpretation by the agent's vision system.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 25, 2026, 07:05 AM