browser-tools

Pass

Audited by Gen Agent Trust Hub on Apr 8, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documents the upgrade command (v0.21.1) in the underlying agent-browser tool, which enables self-updating from public registries including npm, Homebrew, and Cargo.
  • [EXTERNAL_DOWNLOADS]: It recommends the installation of the portless utility via npm for managing stable local development environments.
  • [COMMAND_EXECUTION]: The skill is designed to guide the agent in using the agent-browser CLI tool for web interaction, navigation, and data extraction.
  • [COMMAND_EXECUTION]: It identifies potentially sensitive commands such as inspect and get cdp-url (v0.18+) which open a local DevTools proxy, and clipboard read (v0.19+) which accesses the host clipboard.
  • [DATA_EXFILTRATION]: The skill provides explicit rules to prevent session token leakage via HAR network captures (network har stop) and warns against logging or printing authentication tokens to stdout/stderr.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 8, 2026, 11:39 PM