Browser automation via MCP tools. ALWAYS use these tools for ANY web task - navigating sites, clicking, typing, filling forms, taking screenshots, or extracting data. This is the ONLY way to control the browser.
67
80%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Critical
Do not install without reviewing
Fix and improve this skill with Tessl
tessl review fix ./packages/agent-core/mcp-tools/dev-browser/SKILL.mdSecurity
2 findings: 1 critical severity, 1 high severity. Installing this skill is not recommended: please review these findings carefully if you do intend to do so.
Detected high-risk code patterns in the skill content — including its prompts, tool definitions, and resources — such as data exfiltration, backdoors, remote code execution, credential theft, system compromise, supply chain attacks, and obfuscation techniques.
The repository includes explicit instructions to capture authentication request headers, capture responses, replay authenticated API requests from the browser context, and write those sensitive details to ignored tmp files—patterns that enable credential harvesting and large-scale data exfiltration.
The skill handles credentials insecurely by requiring the agent to include secret values verbatim in its generated output. This exposes credentials in the agent’s context and conversation history, creating a risk of data exfiltration.
The skill's action schema and examples show plaintext credentials placed directly into browser_script/findAndFill "text" fields (e.g., "secret123", "mypassword"), which requires the LLM to handle and output secrets verbatim in generated tool calls.
Low
Low-risk findings.
1 low severity finding. Worth noting, but not necessarily harmful.
The skill exposes the agent to untrusted, user-generated content from public third-party sources, creating a risk of indirect prompt injection. This includes browsing arbitrary URLs, reading social media posts or forum comments, and analyzing content from unknown websites.
SKILL.md’s required “browser automation” runtime path allows visiting arbitrary user-supplied URLs and then ingesting the resulting page accessibility text/snapshots back into the agent context (outsider-authored web content via browser_snapshot / browser_script snapshot), which can include prompt-injection style free text from the remote site.
2cf74d0
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.