chrome-bridge-automation
Pass
Audited by Gen Agent Trust Hub on Mar 25, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses
npx @midscene/web@1to fetch and execute the Midscene automation tool from the NPM registry at runtime. This is an intended component of the skill's infrastructure and originates from the vendor.\n- [COMMAND_EXECUTION]: Shell commands are used to invoke the Midscene CLI for browser interaction and screenshot capture.\n- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted web content via visual grounding to make operational decisions.\n - Ingestion points: Page content is ingested through screenshots and processed by the
actcommand as specified inSKILL.md.\n - Boundary markers: No specific delimiters or instructions are used to distinguish external web content from the agent's internal instructions.\n
- Capability inventory: The skill possesses the
Bashtool and has control over the user's live browser session, including logged-in states.\n - Sanitization: Visual data and text from web pages are not sanitized or filtered before interpretation by the agent's vision system.
Audit Metadata