T09 · Insecure Skill Coding Practices
- Location
references/examples.md:128- Finding
Untrusted Webpage Content Can Control Privileged Browser Actions
- Content
View full analysis
{ // Prepare context for vision model const prompt = this.buildReasoningPrompt(task, state, history); // Send annotated screenshot and prompt to vision model const response = await this.visionModel.analyze({ image: state.annotatedScreenshot, prompt, systemPrompt: this.getSystemPrompt(), }); // Parse action from response return this.parseAction(response, state); } private buildReasoningPrompt( task: WebTask, state: AnnotatedPageState, history: StepHistory[] ): string { let prompt = `## Task ${task.instruction} ## Current Page URL: ${this.page.url()} Title: ${await this.page.title()} ## Interactive Elements (marked on screenshot) `; for (const mark of state.marks) { prompt += `[${mark.id}] ${mark.element.type}: "${mark.element.label}" `; if (mark.element.attributes['href']) { prompt += `(href: ${mark.element.attributes['href']})`; } prompt += '\n'; } if (history.length > 0) { prompt += '\n## Previous Actions\n'; for (const step of history.slice(-5)) { prompt += `Step ${step.step}: ${step.action.type}`; if (step.action.target) prompt += ` on "${step.action.target}"`; if (step.action.value) prompt += ` with value "${step.action.value}"`; prompt += ` - ${step.result.success ? 'Success' : 'Failed'}\n`; } } prompt += ` ## Instructions 1. Look at the annotated screenshot 2. Identify which element to interact with based on the task 3. Choose the appropriate action type 4. Provide your reasoning ## Response Format { "reasoning": "explanation of why this action", "action": { "type": "clic ...[truncated 2858 chars]- Remediation
View remediation
